Back to skill

Security audit

Work Productivity Nano Pdf Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a low-impact workflow/documentation skill, but its activation wording is too broad and may trigger on unrelated PDF or editing requests.

Installers should understand that this skill may be selected for ordinary PDF, editing, or workflow requests because of broad triggers. It appears safe as a guidance-only skill, but the publisher should narrow activation wording or require explicit invocation to avoid irrelevant routing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad and include generic terms like 'nano', 'pdf', 'edit', and 'natural language instructions', which can cause the skill to activate outside its intended scope. In an agent ecosystem, ambiguous routing can misapply this skill to unrelated requests, increasing the chance of unsafe workflow substitution, incorrect handling, or bypass of more appropriate specialized skills.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match common user requests involving PDFs, editing, or generic workflow help, which can cause the skill to activate outside its intended scope. In an agent environment, overbroad activation increases the chance of unintended instruction injection, user confusion, or the wrong skill handling sensitive tasks.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description is broad enough to match many ordinary requests about work, PDFs, editing, analysis, or implementation support, which can cause the skill to activate outside its intended niche. In an agent routing system, this kind of overmatching can hijack unrelated tasks, increase prompt-surface exposure, and cause unsafe or low-relevance instructions to be injected into normal user flows.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keyword list includes highly ambiguous everyday terms such as 'nano', 'pdf', 'edit', 'natural', 'language', and 'instructions', any of which may appear in benign conversations unrelated to this skill. This makes accidental invocation likely and increases the chance that the skill's workflow or guidance will interfere with unrelated tasks or broaden the attack surface for prompt-routing manipulation.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger sentences are written as natural-language requests rather than clearly bounded invocation syntax, so an agent may interpret ordinary quoted text or paraphrased user requests as a signal to load the skill. This ambiguity makes routing less predictable and compounds the risk created by the already broad description and keyword set.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keyword list includes overly broad everyday terms such as "nano", "pdf", "edit", "natural", and "language", which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance the agent applies the wrong workflow, injects irrelevant instructions into another task, or interferes with higher-priority skills, creating security and reliability risks through unintended behavior.

Vague Triggers

High
Confidence
92% confidence
Finding
The skill description says it should be used when users ask for broad terms like work-productivity, nano, pdf, or edit, without clearly bounding the task scope. This makes the activation condition ambiguous and can cause the skill to be selected for unrelated requests, which is dangerous because it expands the instruction surface and may override more appropriate skills or produce misleading actions.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt trigger phrase is extremely broad and includes common terms like "help me," "workflow," and product/domain keywords that are likely to appear in ordinary user requests. Combined with allow_implicit_invocation: true, this increases the chance the skill is invoked unintentionally, causing prompt injection of this skill’s instructions or unexpected routing into the skill during unrelated conversations.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentences are written in broad, natural language phrasing that overlaps with ordinary user requests, which can cause the skill to activate when the user did not explicitly intend to invoke it. In an agent ecosystem, unintended invocation can route tasks into the wrong workflow, causing misleading outputs, context leakage across tools, or bypass of safer task-specific routing controls.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The usage keywords include very generic terms such as 'nano', 'pdf', 'edit', and 'work-productivity', which are common across many unrelated requests and can make this skill match far outside its intended scope. Overbroad keyword activation increases the chance of accidental tool selection, producing irrelevant guidance or interfering with correct routing to more appropriate and safer skills.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.