Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with broad activation wording, but it does not request special access, persistence, credentials, or hidden execution.

Before installing, be aware that this skill may activate on fairly broad workflow or knowledge-related requests. It appears safe as a guidance helper, but users who want precise routing should narrow its trigger phrases or invoke it explicitly only for ontology-style workflow design and related skill-authoring tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentence is generic enough to match ordinary user requests about getting help or needing a workflow, which can cause the skill to activate outside its intended domain. Over-broad activation increases the chance that this skill intercepts unrelated tasks, leading to prompt-scope confusion, unintended instruction injection surface, or misuse of the workflow in contexts it was not designed to handle.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation guidance describes broad keywords and sample invocations but does not define when the skill should not be used, leaving routing ambiguous. In an agent ecosystem, unclear scope can cause inappropriate tool selection and expand exposure to adversarial or irrelevant inputs, reducing reliability and potentially bypassing safer, more specialized skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad, generic, and likely to match ordinary user requests such as asking for a 'practical workflow' or help 'fixing bugs' and 'hardening'. This can cause the skill to activate outside its intended niche, potentially overriding more appropriate skills or injecting ontology-specific workflow behavior into unrelated tasks.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger keywords are broad terms like "knowledge," "graph," and "creating," which are common across many unrelated requests. This can cause unintended invocation of the skill, leading the agent to apply the wrong workflow or expose users to irrelevant or lower-quality guidance when a more appropriate skill should have been selected.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The description says to use the skill for very broad categories such as work-productivity, ontology, typed, knowledge, graph, or general workflow support. This ambiguity makes routing unreliable and increases the chance the skill is selected for unrelated tasks, which is a security and safety concern because misapplied skills can override more suitable safeguards or produce misleading outputs.

Vague Triggers

Low
Confidence
82% confidence
Finding
The example trigger sentence begins with a generic phrase like "Help me," which does little to distinguish when this skill should be invoked. In systems that rely on examples for routing, vague examples can bias selection toward this skill for ordinary requests, increasing accidental invocation risk.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes very broad, common terms such as "typed", "knowledge", "graph", and "creating", which can cause the skill to activate for unrelated requests. This increases the chance of accidental routing, causing the agent to apply the wrong workflow, produce irrelevant actions, or overshadow a more appropriate skill in contexts involving implementation or safety guidance.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt is overly broad and written in common-language terms that can match many ordinary user requests, increasing the chance of unintended or implicit skill invocation. Because implicit invocation is enabled, the skill may activate outside clearly scoped ontology/workflow tasks, causing unexpected behavior, overreach, or unsafe delegation based on weak intent matching.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger sentence is broad and resembles ordinary user language, which can cause the skill to activate in contexts where the user did not explicitly intend to invoke it. In an agent environment, unintended activation can misroute tasks, override more appropriate skills, or cause the system to apply this workflow to unrelated requests.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger descriptions are ambiguous and insufficiently constrained, so the skill may match a wide range of unrelated productivity or implementation requests. This increases the chance of accidental invocation, which can degrade agent reliability and create unsafe tool-selection behavior by causing the wrong skill to take control.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.