Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but it does not request sensitive access, persistence, commands, or data handling.

Before installing, consider narrowing the activation wording or disabling implicit invocation so this helper is used only for ontology-style workflow tasks. The inspected artifact does not show hidden execution, credential use, persistence, or destructive behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentences are broad, generic, and overlap with normal user requests such as asking for practical help or workflows. In an agent-routing environment, this can cause accidental invocation of the skill outside its intended scope, leading to misrouting, unexpected behavior, or inappropriate handling of unrelated tasks. Because this is a work-productivity helper with wide topical keywords, the surrounding context makes over-triggering more likely rather than less dangerous.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad enough to match ordinary requests such as asking for a practical workflow or implementation help, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad invocation increases the chance of unintended instruction injection, task hijacking, or the skill being selected for unrelated requests where its guidance may be unsafe or misleading.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description is extremely broad and matches generic requests like workflow help, analysis, implementation support, and common productivity topics. In agent routing systems, this can cause unintended invocation on unrelated user requests, leading to prompt-scope hijacking, interference with more appropriate skills, and unsafe overreach into tasks the skill was not narrowly designed to handle.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes highly generic terms such as 'typed', 'knowledge', 'graph', 'structured', 'memory', 'creating', and 'bug fix', which are common across many unrelated tasks. Such unspecific triggers increase the chance of accidental activation and routing collisions, allowing this skill to intercept broad classes of requests and potentially influence agent behavior outside its intended domain.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger sentences are phrased as ordinary help requests and do not define operational boundaries, making them easy to match in benign everyday conversations. This broad phrasing can train or bias routing toward over-selection of the skill, increasing unintended invocation frequency and reducing reliability of the overall skill ecosystem.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger keyword list includes very broad terms such as "knowledge", "graph", and "creating", which are common in unrelated user requests. This can cause the skill to activate unexpectedly, leading to misrouting, prompt pollution, or the insertion of irrelevant workflow instructions into tasks that did not request this skill.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description defines activation conditions in an overly broad way, covering generic requests for practical workflows, artifacts, checklists, analysis, or implementation support. Because these are common across many tasks, the skill may be selected outside its intended domain, increasing the chance of incorrect assistance, interference with safer/more relevant skills, and reduced reliability of agent behavior.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation while providing only a very broad, non-specific description of when it should activate. This creates a realistic risk that the agent will invoke the skill for loosely related everyday requests, causing unintended prompt injection surface expansion, incorrect tool selection, or unexpected handling of user data.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt contains broad natural-language phrasing such as general help with workflows, bugs, safety, reliability, checklists, analysis, and implementation support. Because these terms overlap heavily with ordinary user requests, the skill may be selected in contexts the user did not intend, increasing the chance of overbroad activation and unsafe prompt steering.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is so broad and natural-language-like that it could match ordinary user requests unrelated to this specific skill, causing accidental invocation. In an agent ecosystem, overbroad activation can route tasks into the wrong workflow, leading to unintended actions, confusing outputs, or interference with higher-priority safety-relevant skills.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger description does not clearly define when the skill should and should not activate, so the router may invoke it for loosely related requests. This ambiguity increases misrouting risk and can degrade reliability, especially because the skill advertises broad help with workflows, analysis, implementation support, and adjacent tasks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.