Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with broad activation wording, but it does not install code, run commands, persist agents, or request sensitive access.

Before installing, understand that the skill may activate for some generic workflow or knowledge-graph-related requests. It appears safe as a guidance-only skill, but tighter trigger wording would make it less likely to be invoked accidentally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence is broad enough to match common user requests for help or workflows, which can cause accidental skill activation outside its intended domain. In an agent ecosystem, over-broad activation can route unrelated tasks into this skill, leading to inappropriate guidance, prompt hijacking opportunities through unexpected contexts, or denial of correct tool selection.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation guidance relies on a long, generic keyword list and loose example phrases without clear boundaries for when the skill should or should not run. This increases unintended invocation risk and makes it easier for unrelated prompts containing generic terms like 'help', 'workflow', or 'bug fix' to activate the skill, reducing safety and predictability.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad, generic, and partially templated around common help-seeking language, which increases the chance that unrelated user requests will invoke this skill unintentionally. In an agent ecosystem, unintended invocation can route user data or tasks into the wrong workflow, causing incorrect actions, confusing outputs, or unsafe automation chains.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description is broad enough to match many ordinary productivity or implementation-support requests, which can cause the agent to invoke this skill outside its intended scope. Over-broad routing increases the chance of prompt/skill hijacking, misapplication of workflow instructions, and unintended interception of user tasks that should be handled by more specific or safer skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keywords include generic terms such as "knowledge," "graph," "structured," "creating," and "bug fix," which are common across many unrelated requests. In an agentic environment, such ambiguous triggers can cause this skill to activate for broad classes of prompts, leading to incorrect tool selection, policy bypass through skill confusion, or capture of requests better handled by a more constrained skill.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords are very broad and common terms like "knowledge", "graph", "structured", and "bug fix", which can match many unrelated user requests. This can cause accidental invocation of the skill in contexts where it is not appropriate, increasing the risk of confusing behavior, misrouting, or unintended disclosure of workflow guidance in the wrong task context.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description defines an expansive activation scope covering multiple generic topics and broad requests for workflows, checklists, analysis, or implementation support without clear exclusion criteria. Ambiguous routing criteria can cause the skill to be selected for requests outside its intended scope, reducing reliability and potentially interfering with safer or more appropriate skills.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt contains a very broad natural-language trigger phrase tied to common concepts like work productivity, workflows, and practical help. Because implicit invocation is enabled, ordinary user requests are more likely to match and activate this skill unintentionally, creating prompt-routing confusion and increasing the chance that this skill handles requests outside the user's explicit intent.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is phrased so broadly that it can activate on common help-seeking language rather than a narrowly scoped ontology-workflow request. This creates prompt/skill over-selection risk: the agent may invoke this skill in unrelated contexts, causing inappropriate behavior, scope creep, or unsafe bypass of better-matched skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation guidance lacks clear boundaries for when the skill should not run, so many adjacent work-productivity requests could match even if they are unrelated to typed ontology workflows. In a multi-skill agent, ambiguous routing increases the chance of accidental invocation, irrelevant outputs, and interference with more appropriate or safer skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.