Back to skill

Security audit

Work Productivity Nano Pdf Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a non-executable workflow helper, with broad activation wording that users should review but no hidden code, credential access, persistence, or destructive behavior.

Before installing, check whether you are comfortable with this skill being eligible for implicit activation on broad PDF or editing-related prompts. It appears safe as a guidance-only helper, but tighter trigger phrases would reduce accidental use in unrelated tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad enough to match common user requests involving PDFs, editing, workflows, or general productivity, which can cause this skill to activate outside its intended scope. Over-broad activation increases the chance of unintended instruction injection into unrelated tasks, user confusion, and misuse of the skill in contexts where its assumptions or safeguards do not apply.

Vague Triggers

High
Confidence
90% confidence
Finding
The example trigger phrases are broad, natural-language prompts that overlap with ordinary user requests about PDFs, editing, and workflow help. This can cause unintended skill activation or routing collisions, leading the agent to invoke this skill when the user did not explicitly request it, which is a prompt-routing and control-boundary issue rather than a code-execution flaw.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger section provides examples but does not define hard scope constraints, exclusions, or disambiguation behavior. In an agent ecosystem, that ambiguity increases the chance of accidental invocation, misrouting, or skill hijacking by unrelated user prompts that happen to match the broad patterns.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description contains very broad trigger terms like 'work-productivity', 'pdf', 'edit', 'analysis', and 'implementation support', which are common in ordinary user conversations. This creates a significant risk of accidental or inappropriate activation, causing the agent to route unrelated requests into this skill and potentially override more appropriate, narrowly scoped behaviors.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes highly ambiguous terms such as 'nano', 'pdf', 'edit', 'natural', 'language', and 'instructions', all of which are likely to appear in benign, unrelated prompts. In a skill-routing system, this broad matching can cause frequent collisions and unintended invocation, increasing the chance of misrouting user intent and degrading safety and reliability across the agent environment.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger sentences are vague and effectively demonstrate that broad natural-language requests should invoke the skill without clear boundaries. This encourages overbroad activation behavior and makes it harder for maintainers or routing systems to distinguish intentional use from ordinary discussion of PDFs, workflows, or bug fixing.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keyword list is overly broad and includes common terms such as "nano", "pdf", "edit", "natural", "language", and "instructions", which can match many unrelated user requests. This increases the chance of accidental skill activation, causing inappropriate routing, instruction interference, or unexpected use of this skill in contexts where it does not belong.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The description says to use the skill when users ask for broad categories like work-productivity, nano, pdf, or practical workflow support, but it does not define what requests are out of scope. Ambiguous enablement criteria can lead to over-selection of the skill, which may inject irrelevant workflow guidance into unrelated conversations and reduce system reliability.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger phrases are all positive examples and are themselves broad, offering no counterexamples or boundary conditions to prevent accidental matching. Without negative examples, integrators or routing logic may interpret the examples too loosely and activate the skill for vaguely similar requests.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt uses a very broad natural-language trigger phrase tied to common terms like 'help me' and generic workflow/productivity language, which increases the chance of unintended or implicit invocation. Because implicit invocation is enabled, this can cause the skill to activate in routine conversations where the user did not specifically intend to use it, expanding the attack surface and creating routing or prompt-confusion risks.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences are broad, natural-language phrases that can match ordinary user requests beyond the intended skill scope, increasing the chance of accidental or opportunistic invocation. In an agent ecosystem, overbroad routing can cause the wrong skill to activate, exposing users to unintended behavior, confusing outputs, or unsafe workflow execution without explicit user intent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.