Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-only workflow helper with a routing-quality issue, but it does not request dangerous access or hide behavior.

Before installing, be aware that this skill may be selected too often because its routing text is broad. It appears safe to use as a workflow/planning aid, but the publisher should narrow triggers to explicit ontology or typed-workflow requests to reduce accidental invocation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentence is broad and natural-language-like enough that it could activate in ordinary user conversations unrelated to this specific skill. In an agent-routing context, overly permissive triggers can cause unintended invocation, leading to incorrect tool selection, prompt-scope confusion, or the skill influencing workflows it was not meant to handle.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger guidance lacks precise boundaries for when the skill should and should not activate, which increases the chance of accidental matching across common productivity requests. Because this is a workflow-helper skill with broad terms like 'help me' and 'practical workflow,' misrouting could cause the agent to apply inappropriate instructions or override a more relevant skill.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match many ordinary productivity or workflow requests, which can cause the skill to activate outside its intended scope. Over-broad invocation increases the chance of unintended routing, prompt/context capture, and misuse of the skill in situations where a more specific or safer skill should handle the request.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description is broadly scoped around common terms like work-productivity, workflow, checklist, analysis, and implementation support, making it likely to activate for many unrelated requests. Overbroad routing can cause the wrong skill to take control of conversations, leading to unsafe or irrelevant guidance and making higher-assurance, domain-specific skills less likely to be used.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword trigger list includes highly generic terms such as knowledge, graph, structured, memory, creating, and bug fix, which are common across many benign and sensitive domains. This creates a substantial risk of accidental invocation on unrelated requests, broadening the skill's effective authority and potentially interfering with safer domain-specific handling.

Vague Triggers

Medium
Confidence
91% confidence
Finding
触发关键词包含大量高频、通用词汇,如“knowledge”“graph”“creating”“bug fix”等,容易与许多普通请求或其他技能的适用范围重叠,导致该技能被过度触发。虽然这不直接造成代码执行类风险,但会带来错误路由、越权介入不相关任务、以及让用户在错误上下文中接收不合适建议的安全与可靠性问题。

Vague Triggers

Medium
Confidence
88% confidence
Finding
技能描述将适用场景定义得较宽,如用户只要提出 work-productivity、ontology、typed、knowledge、graph 或需要流程/分析/实现支持即可使用,这使技能边界模糊。模糊边界会增加误触发概率,尤其在多技能环境中可能覆盖其他更专用技能,造成错误指导、结果污染或对安全敏感任务的不当介入。

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt is framed with broad, common-language terms like 'help me' and generic workflow/productivity concepts, which can cause the skill to activate for many unrelated user requests. This creates prompt-routing risk: the system may invoke the skill in contexts the user did not intend, exposing the conversation to unnecessary instructions or behavior from this skill.

Vague Triggers

Medium
Confidence
96% confidence
Finding
Enabling implicit invocation without clear constraints allows the platform to auto-select this skill based on loose semantic similarity rather than explicit user intent. In a skill with broad productivity and workflow language, this increases the chance of unintended activation and prompt-scope expansion, which can interfere with normal assistant behavior or introduce unreviewed instructions into unrelated conversations.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence begins with a very broad natural-language pattern ('Help me ...') that overlaps with ordinary user requests and can cause the skill to be invoked unintentionally. In an agent ecosystem, overly generic triggers increase the chance of routing unrelated tasks into this skill, which can lead to incorrect automation, confusing outputs, or unsafe chaining with other skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation description uses a broad generic request form ('I need a practical workflow for ...') without clearly constraining what kinds of workflows or topics belong to this skill. That weak trigger scope can cause false-positive activations across many work-productivity requests, reducing reliability and potentially misdirecting sensitive or higher-risk tasks into a generic helper skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.