Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with broad trigger wording, but no hidden commands, credential use, persistence, or data exfiltration.

Install only if you want a general ontology/workflow helper. Be aware it may be invoked more often than intended because its triggers include broad terms like knowledge, graph, creating, and bug fix; users or maintainers should narrow activation wording if routing precision matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad and map to common user requests such as asking for help or needing a practical workflow. In an agent-routing system, this can cause unintended activation of the skill for unrelated conversations, leading to incorrect handling, prompt-context pollution, or bypass of more appropriate skills. The surrounding skill context does not make this catastrophic, but the generic work-productivity/ontology wording increases overlap risk.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests such as asking for help, practical workflows, or bug fixes, which can cause this skill to activate outside its intended scope. In an agent ecosystem, over-broad activation can route unrelated prompts into this skill, creating prompt confusion, reducing reliability, and potentially causing unsafe delegation if the skill is later extended with higher-risk behaviors.

Vague Triggers

High
Confidence
97% confidence
Finding
The manifest description contains very broad activation cues such as generic domains and common user intents like needing a workflow, checklist, analysis, or implementation support. In systems that auto-select skills from natural language, this can cause the skill to activate on routine requests outside its intended scope, leading to prompt-surface expansion, unintended instruction precedence, and possible interference with more appropriate skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keywords are highly generic terms such as 'knowledge', 'graph', 'structured', 'creating', and 'bug fix', which commonly appear in unrelated requests. This makes over-triggering likely, causing the skill to match a wide range of ordinary conversations and potentially override safer or more relevant skills in multi-skill environments.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger sentences use vague invocation patterns like 'Help me' and 'I need', combined with copied requirement text, which trains or encourages routing on weak semantic matches rather than explicit intent. While less severe than the manifest and keyword issues, these examples still broaden activation and increase the chance of accidental invocation.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are overly broad and include common terms such as "knowledge", "graph", "structured", and "creating", which can match many unrelated user requests. This can cause unintended skill activation, leading the agent to apply the wrong workflow, override more appropriate skills, or expose users to irrelevant automation and guidance.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says the skill should be used for broad topics like work-productivity, ontology, typed, knowledge, graph, or whenever the user needs practical workflow or analysis support, which creates unclear activation boundaries. Ambiguous scope increases the chance of accidental routing and may cause this skill to handle requests outside its intended competence or safety assumptions.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt activates on very broad, everyday concepts like work productivity, workflows, and practical help, without meaningful scoping constraints. This can cause the skill to be invoked in many unrelated contexts, increasing the chance of unintended prompt injection exposure, user confusion, or the model applying specialized workflow behavior when it was not requested.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentences are broad enough to match ordinary user requests about workflows, help, or practical guidance, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of prompt routing hijack, unintended tool usage, or the skill influencing tasks where its assumptions and safeguards do not fit.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.