Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overbroad activation wording but no hidden execution, data access, persistence, or destructive behavior.

Install this only if you want an agent to help with ontology-style workflow planning and related productivity artifacts. Be aware that its broad keywords and implicit invocation may cause it to appear for generic workflow, graph, knowledge, or bug-fix requests where a more specific skill might fit better.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad, repetitive, and framed around generic requests like needing a practical workflow or implementation help. This can cause the skill to activate in contexts beyond the author’s intended scope, increasing the chance of inappropriate invocation, context hijacking, or accidental interference with other skills handling unrelated productivity or ontology tasks.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad, generic, and partially malformed, making the skill likely to activate on ordinary user requests that mention common concepts like workflow, bug fixes, or hardening. This creates an overbroad invocation surface that can cause unintended routing, prompt hijacking of unrelated tasks, or accidental use of this skill in contexts the user did not intend.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description is extremely broad, covering generic requests like workflow, checklist, analysis, implementation support, and common domains such as knowledge or graph. This can cause the skill to activate for many unrelated user prompts, leading to prompt hijacking of routing/selection and making it easier for this skill to override more appropriate or safer specialized skills.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords and example phrases are ambiguous and include highly generic terms such as 'knowledge', 'graph', 'structured', 'creating', and 'bug fix'. In a skill-routing system, these broad triggers can match a large volume of normal requests, causing misrouting, over-invocation, and unintended influence over tasks outside the skill's intended scope.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger keywords and example invocations are broad enough to match many generic productivity or knowledge-work requests, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of incorrect routing, unintended instruction application, and interference with more appropriate or safer specialized skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description states activation conditions using very broad categories like work-productivity, ontology, typed, knowledge, and graph, plus any request for practical workflows or analysis support. This ambiguity can cause the skill to capture unrelated tasks, leading to mis-scoping, lower reliability, and possible bypass of more appropriate task-specific controls.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt contains a very broad activation phrase tied to common concepts like work productivity, workflows, and practical help, which can overlap with ordinary user requests. In combination with a generic invocation template, this increases the chance the skill will be selected in contexts the user did not specifically intend, causing prompt hijacking of unrelated conversations or accidental exposure to this skill's behavior.

Vague Triggers

Medium
Confidence
96% confidence
Finding
Enabling implicit invocation without strong activation boundaries allows the platform to auto-select this skill based on ambiguous user language. Because the skill description spans broad terms such as productivity, knowledge, graph, workflow, checklist, analysis, and implementation support, unintended activation becomes substantially more likely and can interfere with user intent or route sensitive tasks into the wrong skill.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is broad enough to match ordinary user phrasing rather than a clearly scoped invocation condition, which can cause the skill to activate in contexts where the user did not explicitly intend it. In an agent ecosystem, unintended activation can lead to irrelevant workflow injection, confusion, or interference with higher-priority skills and safety logic.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger examples are ambiguous and do not define clear scope boundaries, so the routing system may invoke this skill for loosely related requests about productivity, graphs, or general help. That increases the chance of misrouting, producing incorrect assistance, and masking the user's real intent when multiple skills could plausibly match.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.