Back to skill

Security audit

Work Productivity Nano Pdf Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk workflow helper, with the main caveat that its broad trigger wording may cause unintended activation.

Installers should be aware that this skill may activate for general PDF, editing, or workflow requests. Prefer explicit invocation with the skill name when using it, and check that its output is actually relevant to the current Nano PDF-style workflow task.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger sentence is written as a very broad natural-language phrase that overlaps with ordinary user requests, which can cause the skill to activate unintentionally. In an agent ecosystem, overly generic activation text can route unrelated tasks into this skill, leading to confused execution, prompt-scope hijacking, or accidental handling of documents/users outside the intended workflow.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The invocation examples do not define clear boundaries for activation and instead present ambiguous, conversational phrasing. This increases the chance of unintended invocation or priority capture by this skill when a user is merely discussing PDFs, bug fixing, or workflow help, which can degrade safety and reliability in multi-skill environments.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad and overlap with ordinary user language such as 'help me' and 'I need a practical workflow', increasing the chance the skill is invoked when the user did not explicitly intend it. In an agent ecosystem, unintended invocation can cause workflow confusion, irrelevant actions, or accidental processing under the wrong skill, which is a genuine security and safety concern even though it is not overtly malicious.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description uses very broad trigger terms such as 'pdf', 'edit', and generic requests for a 'workflow, artifact, checklist, analysis, or implementation support.' In an agent-routing system, this can cause the skill to activate for many unrelated tasks, leading to unintended delegation, reduced reliability, and possible exposure of user data or task context to an irrelevant skill.

Vague Triggers

High
Confidence
99% confidence
Finding
The keyword list includes highly ambiguous everyday terms like 'nano', 'pdf', 'edit', 'natural', 'language', and 'instructions' with no scope constraints. These terms are common across many unrelated user requests, so they materially increase the chance of over-triggering, incorrect tool selection, and misrouting sensitive or irrelevant work into this skill.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The example trigger phrases are vague and repetitive, and they do not define meaningful activation boundaries beyond broad demand language. This reinforces overly permissive routing behavior and makes it harder for maintainers or automated systems to distinguish legitimate Nano PDF workflow requests from unrelated productivity or editing tasks.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list includes very broad everyday terms such as "nano", "pdf", "edit", "natural", "language", and "instructions", which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance that the skill injects irrelevant workflow guidance into contexts where it was not intended, reducing routing integrity and potentially interfering with other, more appropriate skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says the skill should be used when users ask for broad categories like work-productivity, nano, pdf, or edit, or when they need practical workflow or analysis support for the requirement. This wording lacks clear boundaries and overlaps heavily with common user intents, making accidental invocation more likely and weakening reliable skill selection.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt includes broad, everyday trigger terms such as "help me" and generic productivity/PDF wording, while the policy allows implicit invocation. This can cause the skill to activate in many unrelated conversations, increasing the chance of unintended prompt injection exposure, confusing tool routing, or unreviewed execution in contexts the user did not clearly request.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences are broad enough to match many ordinary requests involving productivity, PDFs, workflows, or implementation help, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of incorrect routing, unintended prompt injection exposure from irrelevant contexts, and user confusion when the agent applies this skill where a narrower skill or direct answer would be safer.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The keyword list contains highly generic terms such as 'nano', 'pdf', 'edit', and 'work-productivity', which are common across unrelated tasks and are not reliable indicators for this specific skill. In a routing system, generic keywords can over-select the skill, causing misfires and increasing the attack surface by funneling unrelated user input through a broader-than-necessary instruction set.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.