Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with broad auto-invocation wording, but no hidden execution, credential access, persistence, or destructive behavior was found.

Installers should be aware that this skill may activate too broadly for general workflow, productivity, graph, memory, or bug-fix prompts. Review whether implicit invocation is acceptable in your environment; otherwise, prefer explicit use of the skill name.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad, generic, and likely to match ordinary user requests unrelated to this specific skill. That can cause unintended invocation or over-selection of the skill, increasing the chance that the agent applies the wrong workflow, misroutes user intent, or exposes downstream actions in contexts the user did not explicitly request.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad, repetitive, and partially templated around generic user requests, which increases the chance that the skill activates outside its intended scope. In an agent ecosystem, ambiguous activation can cause the wrong workflow to run on unrelated tasks, leading to misrouting, unintended actions, or reduced safety controls if the skill is invoked in contexts it was not designed to handle.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description is framed so broadly that it can match many ordinary productivity, workflow, analysis, or implementation requests, causing the skill to be invoked outside its intended niche. Over-broad routing increases the chance of unintended prompt capture, policy shadowing, and unsafe behavior inheritance from a specialized skill in unrelated contexts.

Vague Triggers

High
Confidence
97% confidence
Finding
The keyword list includes highly generic terms such as "knowledge," "graph," "structured," "creating," and "bug fix," which are common across many benign user requests. Ambiguous triggers like these can cause excessive auto-selection of this skill, leading to misrouting and possible interference with more appropriate skills or system behavior.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example triggers use vague conversational openings like "Help me" and "I need a practical workflow," which are common across routine requests and may train or encourage broad invocation patterns. While not directly malicious, they reinforce overmatching behavior and increase the likelihood of the skill activating in contexts far beyond its intended purpose.

Vague Triggers

Medium
Confidence
94% confidence
Finding
触发关键词包含如“typed”“knowledge”“graph”“creating”“bug fix”等高度通用词,且未结合强约束语义或排除条件,容易在大量无关请求中误触发该技能。误触发会让代理在错误上下文中套用该工作流,导致结果偏题、覆盖更合适的技能,或放大后续自动化链路中的错误决策。

Vague Triggers

Medium
Confidence
91% confidence
Finding
技能描述中的适用范围覆盖“work-productivity, ontology, typed, knowledge, graph”以及“practical workflow, artifact, checklist, analysis, or implementation support”等宽泛任务类型,边界非常模糊,也没有说明何时不应启用。这样的定义会增加路由歧义,使代理在不适配场景中调用该技能,影响结果可靠性,并可能间接绕过更专门技能的安全约束或审查流程。

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation without any visible trigger constraints, which can cause the agent to activate in response to broad or only loosely related requests. In a helper skill with generic productivity and workflow language, this increases the chance of unintended routing, prompt-scope expansion, or interference with other skills, especially if downstream behavior is powerful or trusted by default.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt uses very broad phrases such as work productivity, workflow help, practical support, and fixing bugs/hardening, which overlap with many common user requests. Combined with implicit invocation, this can cause the skill to be selected in unrelated contexts, creating misrouting risk and exposing users to behavior they did not explicitly request.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger sentences are broad, natural-language phrases that can match ordinary user requests rather than a narrowly scoped skill invocation. This can cause the skill to activate unexpectedly, leading to misrouting, prompt-surface expansion, and reduced operator control over when the skill is applied.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.