Back to skill

Security audit

Work Productivity Nano Pdf Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but it does not request hidden access, persistence, credentials, or automatic execution.

Install only if you want a general Nano Pdf-style workflow helper. Be aware it may activate on ordinary PDF or editing requests because its trigger terms are broad; explicit skill invocation is safer when you want this behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger examples are broad, natural-language phrases that could match ordinary user requests about PDFs, editing, or workflow help, causing the skill to activate outside its intended niche. In an agent ecosystem, overbroad activation can route unrelated tasks through this skill's instructions, leading to confusion, incorrect behavior, or unintended delegation.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The README defines examples but not hard boundaries, so the activation scope is ambiguous and likely to collide with generic productivity or PDF-related requests. This ambiguity is risky because agents may invoke the skill when a user merely mentions overlapping terms like 'pdf', 'edit', or 'workflow', increasing the chance of misrouting and unintended instruction application.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad enough to match common terms like "pdf", "edit", and generic requests for a "practical workflow", which can cause the skill to activate outside its intended scope. This increases the chance of unintended invocation, prompt shadowing, or routing users into this skill when they were asking for something else, reducing reliability and potentially exposing downstream workflows to irrelevant or unsafe context.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are excessively broad, including generic terms like "nano," "pdf," "edit," "natural," and "language," which are likely to match many unrelated user requests. This can cause the skill to activate outside its intended scope, leading to inappropriate responses, workflow confusion, or interception of requests meant for other skills.

Vague Triggers

High
Confidence
94% confidence
Finding
The manifest description is overly expansive, covering broad categories like work-productivity, practical workflow, checklist, analysis, and implementation support. Such ambiguity increases the chance that routing systems or users invoke this skill for unrelated tasks, effectively expanding its authority beyond the intended Nano PDF workflow use case.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger sentences repeat the same broad requirement language and do not show clear inclusion or exclusion criteria. Without meaningful boundaries or counterexamples, implementers and routing systems have little guidance on when the skill should or should not be selected, increasing accidental invocation risk.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes very common terms such as "nano", "pdf", "edit", "natural", and "language", which are likely to appear in many unrelated conversations. This can cause unintended skill activation, leading the agent to apply the wrong workflow, inject irrelevant instructions, or override more appropriate handling in adjacent contexts.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation description is broad and says to use the skill whenever a user mentions generic concepts like work-productivity, nano, pdf, or edit, without defining exclusion criteria. In an agent system, ambiguous routing increases the chance of misfires, causing the model to select this skill for unrelated tasks and potentially degrade correctness or safety of downstream actions.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The default prompt contains very broad natural-language trigger terms such as "help me" and generic workflow language, which can overlap with ordinary user requests and cause unintended invocation of the skill. Because implicit invocation is enabled, this increases the chance the agent routes unrelated conversations into this skill, potentially exposing users to incorrect automation, prompt hijacking surface, or unexpected behavior.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger phrases are broad natural-language prompts like 'Help me' and 'I need a practical workflow', combined with common terms such as 'nano', 'pdf', and 'edit'. This can cause the skill to activate in many unrelated contexts, leading to unintended invocation, response hijacking of more appropriate skills, and expanded attack surface for prompt-routing abuse or accidental execution.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.