Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overbroad activation wording, but it does not install code, request credentials, persist, exfiltrate data, or run privileged actions.

Installers should understand that this skill may be invoked for broad workflow or ontology-related requests because implicit invocation is enabled and the trigger phrases are loose. Consider narrowing triggers or requiring explicit use of the skill name if precise routing matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger sentence is written as a natural-language help request with very broad terms like 'Help me' and a long generic problem description, which increases the chance that unrelated user prompts could accidentally match and invoke the skill. In an agent ecosystem, unintended invocation can route tasks to the wrong workflow, causing confusing behavior, unnecessary actions, or unsafe automation if the skill proceeds on loosely related input.

Vague Triggers

Medium
Confidence
89% confidence
Finding
This trigger phrase, 'I need a practical workflow for ...', is still broad and lacks firm boundaries on when the skill should activate. Because the skill targets common productivity and workflow concepts, a wide variety of ordinary requests could match, leading to over-triggering and unintended execution in contexts the user did not explicitly select.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are generic and overlap with ordinary user requests about workflows, bug fixing, or hardening. In an agent ecosystem, this can cause accidental invocation of the skill in unintended contexts, leading to prompt-routing errors, confused delegation, or inappropriate handling of user data and tasks.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description is broad enough to match many ordinary productivity, workflow, analysis, and implementation requests, which can cause the agent to invoke this skill outside its intended niche. Over-broad routing is dangerous because it can override more appropriate skills, expand the attack surface for prompt injection through unnecessary skill activation, and degrade reliability in safety-sensitive task selection.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes highly generic terms such as 'knowledge,' 'graph,' 'structured,' 'creating,' and 'bug fix,' which are common across many unrelated requests. This makes accidental or adversarial triggering much easier, increasing the chance that the skill captures prompts it should not handle and interferes with safer or more specialized routing logic.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences use broad request language like 'help me' and 'I need a practical workflow' without showing clear boundaries for valid activation. Such examples train routing behavior toward overmatching, which can normalize activation on loosely related prompts and reduce the precision of skill selection.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger keywords are broad enough to match many ordinary user requests such as 'knowledge', 'graph', 'structured', or 'bug fix', which can cause the skill to activate outside its intended scope. Over-broad activation can route users into an irrelevant workflow, increase prompt-surface exposure, and make downstream behavior less predictable or less safe when multiple skills compete.

Natural-Language Policy Violations

Low
Confidence
75% confidence
Finding
The file is primarily Chinese, but the trigger examples are English-oriented and do not specify language handling or selection. This can cause ambiguous activation and user confusion, increasing the chance of incorrect routing or misunderstanding of the skill's purpose, though it is not a direct code-execution or data-exfiltration risk.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation while providing only a broad, generic description of when it should activate. That creates a real risk of unintended triggering during ordinary user conversations, causing the agent to inject this skill's prompt or behavior outside the user's clear intent and potentially override more appropriate context.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The default prompt uses very broad everyday assistance language such as helping with workflows, checklists, analysis, and implementation support, which overlaps heavily with normal assistant behavior. In combination with implicit invocation, this makes accidental or overly frequent activation plausible, leading to prompt-scope confusion, unexpected instruction injection, and reduced reliability of the host agent.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence begins with a broad everyday phrase ('Help me') combined with generic requirement text, which can cause the skill to activate in many unrelated conversations. This creates prompt-routing confusion and unintended invocation risk, especially in agent ecosystems where trigger matching may be loose or keyword-based.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence is too ambiguous because it describes a broad class of practical workflows rather than a specific activation condition. An agent may misclassify unrelated user requests as in-scope, leading to incorrect tool/skill selection, reduced reliability, and possible exposure of downstream actions or outputs in the wrong context.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.