Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording but no hidden execution, data access, persistence, or destructive behavior.

Before installing, consider narrowing or disabling implicit invocation if you only want this helper used for explicit ontology or typed-workflow requests. The submitted artifacts do not show hidden commands, data collection, persistence, or destructive behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentences are broad, generic, and overlap with common user requests such as asking for help, needing a workflow, or requesting implementation support. This can cause unintended skill activation or over-selection, which is risky because the skill may run in contexts the user did not explicitly intend, increasing the chance of incorrect automation, prompt interference, or misuse of workflow guidance.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are so generic that they can activate on ordinary user requests unrelated to the intended skill, causing accidental invocation and scope overreach. In an agent ecosystem, broad triggers can route unrelated tasks into a workflow with different assumptions, which increases the risk of unintended actions, confusing outputs, or misuse of attached capabilities.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description is written broadly enough to match many ordinary productivity, knowledge, workflow, and implementation requests, which can cause the skill to activate outside its intended niche. Over-broad activation increases the chance of unintended routing, prompt interference, and unnecessary exposure of users to skill-specific instructions in unrelated contexts.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes very generic triggers such as 'typed', 'knowledge', 'graph', 'creating', and 'bug fix', all of which commonly appear in benign requests unrelated to this skill. Ambiguous keywords can cause accidental invocation and misrouting, making the system less predictable and easier to manipulate through prompt wording.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger phrases use everyday language and effectively restate the broad requirement text rather than providing sharply scoped activation examples. This encourages loose matching behavior and makes it easier for unrelated user prompts to resemble a valid trigger, increasing accidental activation risk.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description is extremely broad and overlaps with common productivity, workflow, knowledge, and implementation-help requests. This can cause the skill to be invoked for many unrelated tasks, increasing the chance of incorrect routing, accidental execution in the wrong context, and unsafe reliance on guidance not tailored to the user’s actual need.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The keyword list includes highly generic terms such as 'knowledge', 'graph', 'structured', and 'creating', which are common across many benign requests. Overbroad triggers make mis-invocation likely, potentially exposing users to irrelevant or misleading automation steps and reducing trust in routing and safety controls.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt contains broad, common-language trigger text such as work-productivity and ontology-style workflow phrasing that could match many unrelated user requests. Because the skill also appears designed for practical workflow and implementation support, an overly general trigger increases the chance of unintended activation and prompt injection exposure through ambient conversation rather than explicit user intent.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without tight activation constraints allows the skill to be selected automatically in a wide range of contexts, including ambiguous requests. Combined with the broad prompt language, this can cause unintended tool use, expand the attack surface for adversarial prompt content, and reduce user control over when the skill is engaged.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentences are broad, natural-language phrases that overlap with ordinary user requests, increasing the chance the skill is invoked when the user did not explicitly intend it. In an agent ecosystem, unintended invocation can route tasks into the wrong workflow, causing confused execution, incorrect outputs, or bypass of safer/more specific skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.