Back to skill

Security audit

Work Productivity Nano Pdf Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper, with broad activation wording that users should be aware of but no hidden execution, credential access, persistence, or destructive behavior found.

Installers should expect this skill to influence general PDF or workflow-help requests more often than a narrowly scoped skill would. Review or narrow its trigger terms if precise routing matters, but the inspected artifacts do not show unsafe execution or data-handling behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentence is broad and phrased like a natural help request, which increases the chance that the skill is invoked unintentionally when a user is asking generally about productivity or PDF help. In an agent ecosystem, ambiguous activation can route user tasks into this skill without clear user intent, causing mis-execution, confusion, or inappropriate handling of sensitive documents.

Vague Triggers

Medium
Confidence
91% confidence
Finding
This trigger pattern is ambiguous because it asks for 'a practical workflow' without sufficiently constraining the task domain beyond broad requirement text. Such generic language can overlap with many ordinary user requests, making accidental invocation more likely and reducing predictability in agent behavior, especially where document-related actions may involve private or business-sensitive files.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad and map to common terms like 'pdf', 'edit', and generic workflow-help requests, which can cause the skill to activate in contexts far beyond its intended scope. In an agent ecosystem, overbroad activation can misroute user requests, override more appropriate skills, and create unsafe or misleading automation behavior through unintended invocation.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation guidance does not define clear invocation boundaries, and it frames the skill as applicable to a wide class of practical workflows, artifacts, checklists, and implementation support. This ambiguity increases the chance that an agent selects the skill for unrelated or weakly related requests, reducing reliability and potentially steering users into the wrong workflow or output constraints.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keyword list is overly broad and includes generic terms like 'nano', 'pdf', 'edit', 'natural', and 'language', which can cause the skill to activate in many unrelated conversations. This creates unintended routing and prompt-scope expansion risk, where the agent may invoke this skill outside its intended domain and let untrusted skill instructions influence responses more often than necessary.

Vague Triggers

High
Confidence
95% confidence
Finding
The manifest description uses expansive invocation language like 'use when a user asks for work-productivity, nano-pdf, nano, pdf, edit, or needs a practical workflow, artifact, checklist, analysis, or implementation support,' which is broad enough to match many ordinary requests. This increases the chance of inappropriate skill selection and unnecessary exposure of the agent to skill-specific instructions in contexts unrelated to this requirement.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger phrases are vague and resemble normal conversational wording, so they do not provide a safe or precise activation pattern. Ambiguous examples can train or encourage routing systems to invoke the skill on weak semantic matches, increasing accidental activation frequency.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keyword list is overly broad, including generic terms like "nano", "pdf", "edit", "natural", and "language" that commonly appear in unrelated user requests. This can cause accidental skill activation and prompt-routing hijacks, where the skill intercepts conversations outside its intended scope and influences outputs inappropriately.

Vague Triggers

High
Confidence
93% confidence
Finding
The description activates on broad topical language like work-productivity, nano, pdf, and edit, rather than a tightly defined use case. In a skill-routing system, this increases the chance of overmatching unrelated requests and unintentionally inserting this skill's instructions into contexts where they do not belong.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The manifest uses very broad trigger terms and an expansive default prompt, which can cause the skill to be invoked in situations only loosely related to its intended purpose. Because implicit invocation is enabled, this increases the chance of accidental routing, prompt confusion, or the skill being selected for unrelated user requests, potentially exposing users to inappropriate actions or outputs.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger wording is broad enough to match ordinary user requests about PDFs, editing, or general workflow help, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of unintended routing, prompt interference, and accidental invocation of a skill on unrelated tasks, reducing reliability and potentially exposing downstream tools or instructions in the wrong context.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation text uses vague wording like 'I need a practical workflow' without clear boundaries on subject matter, making it ambiguous when the skill should be selected. In an agent ecosystem, ambiguous routing can let this skill intercept common requests, leading to misapplication of instructions and increasing the attack surface for prompt-selection abuse or unintended behavior.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.