Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with broad activation wording but no code, credentials, persistence, or direct system access.

Installers should be aware that this skill may activate on broad productivity, workflow, graph, knowledge, or bug-fix language. That can be noisy or steer an unrelated request into this template, but the inspected artifact does not itself run commands, read private data, install packages, or modify accounts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad, natural-language prompts that could match ordinary user requests without clear boundaries, causing the skill to activate in contexts the user did not explicitly intend. In an agent ecosystem, this can lead to prompt routing errors, unintended tool invocation, and expansion of the skill's influence over unrelated tasks.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The documented trigger phrases are broad, generic, and partially natural-language prompts that could match ordinary user requests unrelated to this specific skill. That increases the chance of unintended invocation, causing the agent to enter this workflow unexpectedly and potentially override user intent or route sensitive tasks through the wrong skill.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description is broad enough to match many ordinary productivity, workflow, and implementation requests, which can cause the skill to activate outside its intended niche. Over-broad activation increases the chance of prompt hijacking at the routing layer, unintended instruction injection into unrelated tasks, and unreliable tool behavior across normal conversations.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list contains generic terms such as 'knowledge,' 'graph,' 'structured,' 'creating,' and 'bug fix' that are common across many benign user requests. This makes accidental invocation likely, allowing the skill's instructions to influence unrelated sessions and broadening the attack surface for misrouting and unintended prompt behavior.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrases are written like normal conversational requests and include broad language that can easily appear in unrelated user prompts. These examples effectively train routing or implementers to invoke the skill on common wording, increasing false activations and causing the skill to steer tasks it was not meant to handle.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords are overly broad and include generic terms like "knowledge", "graph", "structured", "memory", and "creating", which can match many unrelated user requests. This can cause the skill to activate outside its intended scope, leading to inappropriate guidance, workflow confusion, or accidental interception of requests better handled by other skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt trigger phrase is broad and generic enough to overlap with normal user language about productivity, workflows, knowledge, or practical help. Because implicit invocation is enabled, this can cause the skill to activate unexpectedly, creating prompt injection risk, unintended routing, or disclosure/manipulation opportunities when users did not explicitly request this skill.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger sentences are broad and partially generic, so the skill may activate on ordinary user requests that mention common workflow terms rather than an explicit intent to use this skill. In an agent-routing context, this can cause unintended invocation, prompt hijacking of task selection, or misapplication of the skill to unrelated requests, reducing reliability and potentially bypassing safer or more appropriate skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.