Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with broad activation wording but no evidence of hidden, destructive, credential-seeking, or persistent behavior.

Before installing, consider narrowing the trigger wording or disabling implicit invocation if you want this skill to run only for explicit ontology or typed-workflow tasks. There is no evidence that it runs commands, reads secrets, persists data, or modifies the environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentences are broad, natural-language phrases that overlap with ordinary user requests, which can cause the skill to activate unintentionally outside the author's intended context. In an agent ecosystem, unintended invocation can redirect workflows, override more appropriate skills, or cause the agent to apply this skill's instructions when the user did not explicitly request it, reducing reliability and potentially widening the blast radius of any unsafe downstream behavior.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and close to ordinary user requests, which can cause the skill to activate in situations far outside its intended scope. In an agent ecosystem, this can lead to unintended routing, instruction shadowing, or over-application of this skill to unrelated tasks, reducing safety and increasing the chance that less appropriate workflows influence user-facing behavior.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description is broad enough to match many ordinary requests for workflows, analysis, implementation help, or productivity support, which can cause the skill to be invoked outside its intended niche. Overbroad routing increases the chance of prompt/context hijacking at the skill-selection layer and can suppress more appropriate, narrowly scoped skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes highly ambiguous terms such as 'knowledge,' 'graph,' 'structured,' 'memory,' 'creating,' and 'bug fix,' which appear in many unrelated conversations. This makes accidental or adversarial triggering easier, expanding the skill's reach far beyond its intended context and potentially causing unsafe misrouting.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The example trigger sentences rely on generic opener phrases like 'Help me' and 'I need,' combined with loosely scoped text, which teaches invocation patterns that are not meaningfully constrained. This encourages broad matching behavior and increases the likelihood that unrelated user requests will activate the skill.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger keywords are very broad and overlap with common technical discussion terms such as "knowledge", "graph", "structured", and "bug fix". This can cause accidental activation in unrelated conversations, leading the agent to apply the wrong workflow, produce irrelevant outputs, or override more appropriate skills.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The activation description is vague and does not clearly define inclusion and exclusion criteria. In an agent routing context, ambiguous triggers increase the chance of misclassification, causing the skill to handle requests outside its intended scope and potentially degrading reliability or safety controls.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt is broad, repetitive, and weakly scoped, which increases the chance that the platform will invoke this skill for loosely related user requests. Because the skill is framed as generally helping with workflows, artifacts, analysis, and implementation support, an ambiguous invocation string can cause unintended activation and inappropriate context exposure or action selection.

Vague Triggers

Medium
Confidence
96% confidence
Finding
Enabling implicit invocation without trigger constraints allows the system to auto-select this skill in contexts that only loosely match its description. In a broadly described productivity/knowledge workflow skill, this makes misrouting more likely and can lead to unintended execution paths, confusing outputs, or unnecessary access to user context.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is broad enough to match ordinary user language about needing practical workflow help, which can cause this skill to activate outside its intended scope. Over-broad activation increases the chance of prompt/skill routing confusion, where a user request is silently handled by an only partially relevant skill and receives inappropriate guidance or unintended workflow behavior.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger description and example activators do not define clear boundaries for when this skill should or should not run, and they include generic language that overlaps with many unrelated productivity requests. In an agent ecosystem, ambiguous routing rules can lead to incorrect skill invocation, poor output quality, and accidental exposure of internal workflow assumptions to tasks the skill was not designed to handle.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.