Back to skill

Security audit

Work Productivity Nano Pdf Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with no executable code, credentials, persistence, or hidden data access, though its activation wording is broad.

This skill appears safe to install as a workflow helper, but users or maintainers should narrow its trigger terms and consider disabling implicit invocation so ordinary PDF or editing requests are not routed to it unintentionally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Confidence
94% confidence
Finding
The documented trigger phrases are extremely broad and overlap with ordinary user requests about PDFs, editing, workflows, or practical help. This can cause the skill to activate unintentionally, injecting unrelated instructions into conversations and creating prompt-routing confusion that may override more appropriate or safer skills.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad enough to match ordinary productivity and PDF-related requests, which can cause the skill to activate outside its intended scope. In an agent ecosystem, this creates routing confusion and increases the chance that users receive this workflow instead of a more appropriate or safer specialized skill.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description is broad enough to match common requests about 'work-productivity', 'pdf', 'edit', and general workflow help, which can cause the skill to activate outside its intended niche. In an agent environment, this overreach can silently route many unrelated user tasks through this skill, creating prompt-scope confusion, incorrect tool selection, and elevated risk from unintended instruction injection or misapplied behavior.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes highly generic terms such as 'nano', 'pdf', 'edit', 'natural', 'language', and 'instructions' without scope guards, making accidental invocation likely. Because these words appear in many benign requests, the skill can be selected for unrelated tasks, increasing the chance of inappropriate handling, policy bypass through misclassification, or user confusion about why this skill was chosen.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger sentences are vague and effectively restate broad demand language rather than showing clear invocation boundaries. This makes it harder for maintainers and routing systems to understand what should and should not activate the skill, which can propagate the same overbroad matching problem into production behavior.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes highly generic terms such as "nano", "pdf", "edit", "natural", "language", and "instructions", which overlap with ordinary user requests and many unrelated workflows. This can cause accidental skill activation, routing user input into the wrong workflow, increasing the chance of unintended prompt influence, data mishandling, or confusing outputs in benign contexts.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description says to use the skill for broad categories like work-productivity, nano, pdf, and edit, without clearly defining boundaries or exclusion conditions. Ambiguous invocation guidance increases the likelihood that orchestration layers or users invoke the skill in contexts it was not designed for, leading to misrouting and unreliable behavior rather than direct code execution risk.

Vague Triggers

High
Confidence
95% confidence
Finding
The default prompt is written as a broad natural-language trigger containing generic terms like 'help me' and common workflow/productivity concepts, which can overlap with ordinary user requests. In systems that support prompt-based or semantic routing, this increases the chance of unintended activation, causing the skill to be invoked outside its intended scope and potentially exposing users to incorrect actions, unexpected data flow, or policy bypass through over-broad delegation.

Vague Triggers

High
Confidence
98% confidence
Finding
Enabling implicit invocation without tight activation constraints allows the platform to auto-route normal user requests to this skill based on weak semantic similarity. Because this skill targets broad productivity and PDF workflow tasks, accidental invocation is more likely, which can lead to unintended handling of user content, overreach beyond user intent, and increased attack surface from misrouting in sensitive work-productivity contexts.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences and keywords are broad enough to match many ordinary requests involving PDFs, editing, or generic workflow help, which can cause the skill to activate outside its intended scope. Over-broad invocation increases the chance of misrouting user tasks, shadowing more appropriate skills, and unexpectedly applying this workflow in contexts it was not designed to handle.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.