Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style helper skill with overly broad activation wording, but it does not request dangerous access or perform hidden actions.

Before installing, consider narrowing the trigger wording or disabling implicit invocation if you want to avoid accidental activation. The skill itself appears low risk because it only provides workflow guidance and does not include executable or hidden behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests about productivity, workflows, bug fixing, or hardening, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance that a user is routed into this skill unintentionally, leading to inappropriate handling, prompt interference with other skills, or execution of domain-specific instructions in unrelated contexts.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are very broad and generic, including common requests like 'I need a practical workflow' and 'Help me ... fixing bugs, hardening.' This can cause unintended invocation on ordinary user conversations, leading to prompt hijacking of routing, irrelevant skill activation, and reduced user control over which capability is used.

Vague Triggers

High
Confidence
94% confidence
Finding
The skill description is broad enough to match many ordinary productivity, knowledge, or workflow requests without clear gating conditions. In an agent-routing system, this can cause unintended activation, context capture, or interference with more appropriate skills, reducing reliability and potentially exposing user data to the wrong workflow logic.

Vague Triggers

High
Confidence
97% confidence
Finding
The keyword list contains highly generic terms such as 'typed', 'knowledge', 'graph', 'structured', and 'creating', which are common across many unrelated tasks. This makes the skill easy to trigger accidentally or opportunistically, increasing the chance of routing hijack, prompt-space collision, and execution of the wrong assistance pattern in multi-skill environments.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger sentences are vague and reusable across many requests, so they do not establish a clear boundary for when the skill should activate. Ambiguous examples train routing systems and users toward over-activation, which can degrade correctness and increase the risk of the skill intercepting unrelated tasks.

Vague Triggers

Medium
Confidence
93% confidence
Finding
触发关键词包含 `knowledge`、`graph`、`creating`、`bug fix` 等高度通用词,容易与大量普通任务重叠,导致技能在与本意无关的场景被自动启用。误触发会让代理把不相关请求引导到该技能的工作流,造成错误建议、越权式上下文介入或对更合适技能的覆盖。

Vague Triggers

Medium
Confidence
89% confidence
Finding
技能描述中的启用条件覆盖 `work-productivity`, `ontology`, `typed`, `knowledge`, `graph` 以及“需要实用流程、产物、检查清单、分析或实现支持”等宽泛表述,边界过弱。这样的描述会扩大匹配面,使代理在许多一般性生产力或知识整理请求中错误调用该技能,增加行为偏移和结果不可靠的风险。

Vague Triggers

Low
Confidence
85% confidence
Finding
示例触发句使用了 `Help me...`、`I need a practical workflow...` 这类常见日常表达,并拼接了较长需求描述,容易让路由器把普通求助语句误认为该技能触发信号。虽然主要后果通常是误路由而非直接代码执行,但会降低代理选择正确技能的准确性。

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default_prompt is highly generic and includes broad terms like 'help me' and common workplace concepts, which can cause the platform to invoke this skill for ordinary user requests unrelated to the intended ontology workflow use case. This increases the risk of unintended routing, prompt-surface expansion, and user confusion, especially because the prompt text does not contain strong boundaries or exclusivity conditions.

Vague Triggers

Medium
Confidence
96% confidence
Finding
Enabling allow_implicit_invocation without well-defined trigger constraints allows the skill to be auto-selected in response to loosely related everyday requests. In this file, that risk is amplified by the already broad default prompt and broad domain description, making accidental invocation more likely and potentially displacing more appropriate skills or injecting unintended behavior into normal conversations.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentence is broad enough to match ordinary user phrasing unrelated to this specific skill, which can cause unintended invocation. In an agent setting, over-broad routing can expose users to irrelevant automation, produce misleading outputs, and interfere with safer or more appropriate skills.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The invocation description uses a common request pattern that lacks clear boundaries, making accidental or excessive skill activation likely. This increases prompt-routing ambiguity and can let this skill preempt other tools, reducing reliability and potentially widening the blast radius if the skill later contains unsafe instructions or poor guidance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.