Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks for vulnerabilities and agentic risk

Overview

This appears to be an instruction-only workflow/ontology guidance skill with overbroad activation language but no evidence of hidden execution, data access, persistence, or destructive behavior.

Before installing, be aware that the skill may activate for generic workflow, knowledge, graph, or memory requests. Install it if you want broad ontology/workflow guidance, but prefer explicit invocation or tighter routing if your environment has many skills and you want predictable skill selection.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad, generic requests such as asking for 'a practical workflow' or 'help me' with common productivity topics. This can cause the skill to activate in routine conversations where the user did not explicitly intend to invoke it, leading to misrouting, unexpected behavior, and possible interference with more appropriate or safer skills.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are extremely broad and natural-language-like, such as generic requests for 'practical workflow' and help with common productivity tasks. This can cause the skill to activate unintentionally for unrelated user prompts, leading to prompt hijacking of normal conversations, misrouting, and unnecessary execution of skill behavior beyond the user's intent.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
This README is entirely in Simplified Chinese and does not indicate language negotiation or user opt-in, which can force a locale choice onto users or maintainers who did not request it. In security-sensitive or workflow-routing contexts, language mismatch can increase misunderstanding of scope, triggers, or limitations, raising the chance of accidental misuse.

Vague Triggers

High
Confidence
94% confidence
Finding
The skill description is very broad and includes generic task categories like workflow, checklist, analysis, and implementation support. In agent routing systems, this can cause the skill to be selected for unrelated requests, increasing the chance of inappropriate instruction injection into contexts where the skill was not intended to operate.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords include highly generic terms such as "typed," "knowledge," "graph," "structured," "memory," and "creating," which overlap with many ordinary user requests. This materially increases unintended invocation risk, potentially causing the wrong skill to steer responses, override better-matched skills, or expose users to irrelevant workflow instructions.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrases are vague and effectively restate broad demand text rather than defining precise routing boundaries. Ambiguous examples can train or encourage invocation on loosely related prompts, making misrouting more likely and reducing predictability of agent behavior.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger keywords are extremely broad (for example, common terms like 'knowledge', 'graph', 'structured', and 'creating'), so the skill may activate in many unrelated conversations. This can cause incorrect routing, unexpected skill invocation, and make it easier for a skill to influence conversations outside its intended scope, reducing user control and increasing prompt-surface exposure.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The description says to use the skill whenever broad concepts are mentioned or when related support is needed, which is ambiguous and overreaching. This increases the chance of accidental invocation in ordinary discussions, potentially hijacking agent behavior and causing the system to apply workflow guidance where the user did not request it.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The skill enables implicit invocation, but the metadata does not define a specific, bounded trigger describing when the skill should be auto-selected. That can cause the agent to invoke this skill in overly broad situations based on vague terms like work-productivity, ontology, knowledge, graph, workflow, or analysis, increasing the chance of unintended activation and unsafe cross-context behavior.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger sentence is phrased so broadly that ordinary user language such as 'help me' or 'I need a practical workflow' could activate the skill in contexts far beyond its intended ontology/work-productivity scope. Overbroad activation can cause incorrect routing, unintended handling of unrelated tasks, and increased exposure to prompt or workflow injection through accidental invocation.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The invocation guidance does not clearly define when the skill should and should not be used, leaving activation dependent on vague keywords and broad sample prompts. In an agentic environment, this ambiguity can lead to skill over-selection, mishandling of unrelated requests, and unsafe delegation paths when the skill is invoked without relevant context or constraints.

Static analysis

No suspicious patterns detected.