Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only workflow helper with no executable code, credentials, persistence, or hidden data access, though its activation wording is overly broad.

This skill appears safe to install from a security perspective. Users should be aware that its broad trigger terms and implicit invocation setting may make it appear in unrelated workflow or knowledge-graph conversations, so maintainers should narrow the activation criteria for better routing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description and use criteria are extremely broad, covering generic requests like workflow, checklist, analysis, and implementation support across multiple adjacent concepts. This can cause the skill to activate in situations outside its intended domain, leading to unintended routing, prompt-scope capture, and interference with more appropriate or safer skills.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger keywords include highly generic terms such as 'typed', 'knowledge', 'graph', 'structured', 'memory', 'creating', and 'bug fix' without contextual constraints. These words appear in many unrelated requests, so the skill may be invoked accidentally and overshadow more relevant skills, increasing the risk of incorrect behavior or prompt-routing abuse.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger sentence is broad enough to match ordinary user language, which can cause the skill to activate outside its intended context. In an agent ecosystem, overbroad activation can route unrelated requests through this skill, causing inappropriate behavior, confusing outputs, or interference with safer or more relevant skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The invocation guidance is ambiguous because the examples are long, awkward requirement text instead of a precise trigger contract. This increases the chance that downstream systems or users misunderstand when the skill should run, which can create misrouting, prompt collisions with other skills, and unreliable behavior in multi-skill agent environments.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger sentence is overly broad and reads like ordinary user language rather than a narrowly scoped invocation rule. In an agent-routing context, this can cause accidental activation on unrelated requests, leading the wrong skill to take over handling, produce irrelevant workflow artifacts, or interfere with safer/more appropriate skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are broad, generic, and partially templated around common requests like asking for practical help or workflows. This can cause the skill to activate for unrelated user intents, increasing the chance of unintended routing, confused execution, or inappropriate application of the skill in contexts where it was not meant to be used.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example trigger sentences are themselves vague and repetitive, and they normalize activation on broad phrases rather than clarifying safe boundaries. This reinforces over-triggering behavior and makes it easier for unrelated user input to match the skill, reducing routing precision and potentially exposing users to the wrong workflow guidance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invocation description says to use the skill whenever a user asks for broad concepts like work-productivity, ontology, typed, knowledge, or graph, or for generic artifacts such as workflows, checklists, analysis, or implementation support. Because these categories are expansive and lack exclusion criteria, the skill may activate in many contexts outside its intended scope, leading to misrouting and over-application of the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list includes very generic terms such as "typed", "knowledge", "graph", "structured", and "creating", which can match many unrelated user requests. This can cause unintended skill invocation, routing conversations into an ontology/workflow helper when the user did not ask for it, increasing the chance of irrelevant guidance, prompt-surface expansion, or interference with more appropriate skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The default prompt is overly broad and vague, using generic productivity and workflow language that can match many ordinary user requests unrelated to this specific skill. In combination with a named skill reference and open-ended wording, this increases the chance of unintended routing or invocation, causing the agent to apply this skill outside its intended scope and potentially produce misleading or unsafe assistance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Enabling implicit invocation without meaningful activation constraints allows the platform to trigger this skill automatically based on weak or ambiguous similarity signals. Because the skill description is broad and covers common workplace tasks, this can lead to over-invocation, incorrect tool selection, and accidental exposure of user context to a skill that was not explicitly requested.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation guidance is ambiguous and lacks clear boundaries, so the routing system may select this skill for loosely related requests involving work, knowledge, graphs, or practical help. That increases the chance of prompt/skill misselection, which can degrade reliability and potentially bypass more appropriate controls or specialized handling in other skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file is labeled as a Chinese README, but substantial instructional content and trigger text remain in English, with no note about language preference or user opt-in. This can amount to an implicit language policy choice rather than explicitly allowing the user to select their preferred language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.