Back to skill

Security audit

Work Productivity Nano Pdf Workflow Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but no hidden execution, persistence, credential handling, or destructive behavior was found.

Before installing, consider narrowing or disabling implicit invocation if you only want this skill used for explicit Nano PDF workflow requests. The main risk is accidental activation on generic PDF, editing, or bug-fix prompts, not hidden system access.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger examples are broad enough to match ordinary user requests about PDFs, editing, or practical workflows, which can cause unintended invocation of this skill. In an agent ecosystem, overbroad activation can misroute tasks, override more appropriate skills, or cause this skill to engage in contexts the user did not explicitly choose.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad enough to match common user requests about PDFs, editing, natural language instructions, and bug fixes, which can cause the skill to activate unintentionally. In an agent ecosystem, overbroad activation can redirect user tasks into this workflow unexpectedly, increasing the chance of inappropriate prompt injection, misrouting, or unintended processing.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list is overly broad and includes generic terms like 'nano', 'pdf', 'edit', 'natural', 'language', and 'instructions', which can cause the skill to activate for many unrelated prompts. In an agent environment, this increases the chance of unintended routing, causing the wrong skill to handle sensitive or irrelevant tasks and potentially bypass safer, more specific workflows.

Vague Triggers

High
Confidence
94% confidence
Finding
The description defines invocation criteria in very broad terms, including common words and generic requests for a 'practical workflow, artifact, checklist, analysis, or implementation support.' This makes the skill eligible for many ambiguous user requests, increasing misfires and the possibility that the agent selects this skill when a narrower or safer skill should respond.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keyword list includes very broad everyday terms such as "nano", "pdf", "edit", "natural", "language", and "instructions", which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance that the wrong skill handles user input, leading to unintended actions, confused task routing, or inappropriate access to workflow guidance in contexts where it was not requested.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description says to use the skill for broad categories like work-productivity, nano, pdf, edit, or whenever a user needs practical workflow or implementation support around the requirement, but it does not define clear activation boundaries. This ambiguity can make the orchestrator invoke the skill in loosely related scenarios, increasing the risk of misrouting, accidental overreach, and reduced reliability of agent behavior.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger phrases are themselves broad and repetitive, and they do not illustrate meaningful boundary cases that distinguish valid invocations from unrelated requests. Poor trigger examples reinforce over-matching behavior and make it harder for maintainers or routing systems to constrain activation safely.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The default prompt uses very broad, everyday terms like "help me" and references generic productivity/PDF tasks without meaningful activation boundaries. In systems that support implicit invocation, this can cause the skill to be selected in unrelated conversations, increasing the risk of prompt hijacking, unintended tool use, or disclosure of skill behavior in contexts where the user did not clearly request it.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger sentence begins with a very broad everyday phrase ('Help me ...') that can match many unrelated user requests, increasing the chance that this skill activates outside its intended Nano PDF workflow context. Overbroad activation can cause prompt/skill routing confusion, making the agent apply the wrong workflow or expose users to irrelevant or unsafe actions without clear intent.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentence is too ambiguous to reliably distinguish this skill from other general productivity or workflow-help skills. In agent ecosystems, ambiguous routing conditions can lead to unintended invocation, causing incorrect task handling, user confusion, and potentially unsafe execution paths if the wrong skill is trusted for a sensitive workflow.

Static analysis

No suspicious patterns detected.