Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with overly broad activation wording, but it does not contain executable code, credential handling, persistence, or hidden data access.

Installers should be aware that this skill may activate more often than intended because its triggers include generic terms like knowledge, graph, creating, and bug fix. It is otherwise a low-risk planning helper; consider narrowing triggers or disabling implicit invocation for cleaner routing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and map to common user requests like needing help, practical workflows, bug fixes, or hardening. This can cause the skill to activate in situations outside its intended scope, leading to inappropriate routing, accidental handling of unrelated tasks, and increased exposure if downstream skill instructions are powerful or unsafe.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are generic and map to common help-seeking language, so the skill can be invoked in contexts far beyond its intended scope. In an agent ecosystem, over-broad activation can cause unintended routing, inappropriate application of the skill to unrelated tasks, and increased exposure to prompt-confusion or unsafe workflow execution.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description is broad enough to match many ordinary requests such as workflow help, analysis, implementation support, or productivity tasks. In an agentic system, this can cause the skill to auto-activate outside its intended scope, injecting unrelated instructions and increasing the chance of prompt-surface expansion, policy interference, or unsafe downstream actions.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list contains highly generic terms such as 'knowledge', 'graph', 'structured', 'memory', 'creating', and 'bug fix' that are common across many benign user prompts. This makes accidental triggering likely, which can route unrelated conversations through this skill and expand its influence over model behavior beyond the intended ontology-workflow domain.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger phrases are written as broad natural-language requests that resemble ordinary user prompts rather than clear, bounded invocations. This can normalize overmatching and make the routing layer treat common requests as signals to load the skill, increasing unintended instruction injection and reducing predictability.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords are very broad and include generic terms like 'knowledge', 'graph', 'structured', 'creating', and 'bug fix', which are likely to appear in many unrelated conversations. This can cause the skill to activate outside its intended scope, leading to incorrect routing, user confusion, or the insertion of irrelevant workflow guidance into normal tasks.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation description says to use the skill when users mention broad domains or need 'practical workflow, artifact, checklist, analysis, or implementation support' for the requirement, but it does not define clear inclusion or exclusion boundaries. Because the scope overlaps with many ordinary productivity or engineering requests, the agent may invoke this skill inappropriately and produce off-target guidance.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt is extremely broad and matches common productivity, workflow, knowledge, graph, checklist, analysis, and implementation requests. This can cause the skill to activate in many ordinary conversations where the user did not explicitly request it, creating prompt-scope confusion and increasing the chance that the skill injects unsolicited behavior or guidance into unrelated tasks.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without strict activation constraints allows the platform to auto-select this skill based on vague similarity rather than explicit user choice. Because the skill description and prompt are already broad, implicit invocation materially increases the risk of accidental invocation, prompt injection into unrelated sessions, and unintended influence over agent behavior.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger sentence is broad enough to match ordinary user requests about help, practical workflows, bug fixes, or hardening, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad activation can route unrelated tasks into this skill, creating prompt-selection errors, reducing reliability, and potentially exposing the skill to contexts it was not designed to handle.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.