Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with broad activation wording but no evidence of hidden, destructive, credential-seeking, or persistent behavior.

Installers should know this skill may be selected for some broad productivity or knowledge-graph-related requests where a narrower skill would fit better. Review or tighten the trigger wording if precise routing matters, but the inspected artifacts do not show malicious or high-impact behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentences are broad, generic, and likely to match ordinary user requests unrelated to this specific skill. This can cause unintended auto-invocation or over-selection of the skill, increasing the chance that users receive irrelevant workflow guidance, or that a more appropriate skill is bypassed, which is a real security and reliability concern in agent routing.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad, generic requests such as asking for practical workflow help, which can match ordinary user speech and cause the skill to activate unintentionally. In an agent ecosystem, overbroad activation can route unrelated tasks into this skill, leading to prompt-scope confusion, incorrect workflow execution, and increased exposure to downstream risky instructions or data handling.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description uses very broad terms such as work-productivity, knowledge, graph, checklist, analysis, and implementation support, which can cause the skill to activate for many unrelated user requests. Overbroad routing is dangerous because it can override more appropriate specialized skills, leading to incorrect handling, policy drift, or unsafe guidance in contexts the skill was not designed for.

Vague Triggers

High
Confidence
99% confidence
Finding
The trigger list contains generic keywords like typed, knowledge, graph, structured, memory, creating, and bug fix, plus broad example trigger sentences. These terms are common across many benign requests, so the skill may be invoked far outside its intended scope, increasing the chance of misrouting, confusing agent behavior, and accidental interception of tasks better handled by safer or more specific skills.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger keywords include broad, generic terms such as "knowledge", "graph", "structured", and "creating", which can match many unrelated user requests and cause unintended activation. In an agent environment, over-broad routing can invoke the wrong skill, producing irrelevant guidance or bypassing more appropriate specialized handling.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The description says the skill should be used when users mention broad domains like work-productivity, ontology, typed, knowledge, or graph, or when they need general workflow or analysis help. This makes the activation boundary ambiguous and increases the chance that the skill is selected for loosely related tasks, which can degrade reliability and lead to unsafe or misleading task delegation.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt is overly broad and includes generic phrases like 'help me' and common productivity language, which can cause the skill to be invoked in situations unrelated to the intended task. Because implicit invocation is enabled, this increases the chance of accidental routing, prompt hijacking of user intent, or the skill being selected when a more appropriate or safer skill should handle the request.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence begins with a very broad everyday request pattern ('Help me ...') and includes generic productivity language, which can cause the skill to activate outside its intended ontology/workflow scope. In an agent routing context, overbroad activation increases the chance of misfires, unintended tool/skill selection, and confusing or unsafe downstream behavior when the wrong skill handles a user request.

Vague Triggers

Medium
Confidence
91% confidence
Finding
This trigger sentence is too ambiguous because it frames invocation around a vague request for a 'practical workflow' without clearly limiting the exact task or subject matter. In a skill ecosystem, ambiguous invocation criteria can cause accidental activation on unrelated work-productivity requests, reducing reliability and potentially exposing users to irrelevant automation or incorrect guidance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.