Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording but no hidden execution, persistence, credential use, or destructive behavior.

Installers should know this skill may be invoked more often than intended because its triggers include generic terms like knowledge, graph, structured, memory, creating, and bug fix. Consider tightening activation wording or requiring explicit use of the skill name, but the inspected artifacts do not show malicious or privileged behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are generic and closely resemble ordinary user requests, which increases the chance the skill is invoked when the user did not explicitly intend to use it. In an agent ecosystem, unintended invocation can route sensitive work through the wrong workflow, causing incorrect actions, over-collection of context, or unexpected processing of user data.

Missing User Warnings

Low
Confidence
75% confidence
Finding
The README advertises keywords such as 'memory' and graph/knowledge handling but does not clearly disclose whether user data may be persisted, linked, or reused across sessions. This can create a transparency and privacy issue because users may provide sensitive operational details without understanding the retention or structured storage implications.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match ordinary productivity and workflow requests, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad routing can misapply ontology- or workflow-specific guidance to unrelated tasks, increasing the chance of unsafe automation, user confusion, or prompt hijacking through generic invocation text.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description is broad enough to match many ordinary requests about productivity, knowledge, graphs, bug fixes, or implementation help, which can cause the skill to activate outside its intended scope. Overbroad routing increases the chance that this skill will intercept unrelated tasks and apply the wrong workflow, creating prompt-selection errors and potentially bypassing more appropriate, narrower safety guidance.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes very generic terms such as 'typed', 'knowledge', 'graph', 'structured', 'memory', 'creating', and 'bug fix', which are common across many unrelated user prompts. In a skill-routing system, such broad triggers can cause frequent false activations, making the agent select this skill in unintended contexts and increasing the risk of inappropriate instructions being applied.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger phrases use natural, everyday wording and largely restate broad demand language instead of demonstrating clear activation boundaries. This reinforces ambiguous routing behavior and teaches downstream systems or authors to invoke the skill for loosely related requests, which can degrade safety and correctness through misclassification.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords are broad and include common terms such as "knowledge", "graph", "structured", and "creating", which can overlap with many ordinary requests. This can cause accidental invocation of the skill in unrelated contexts, leading to inappropriate workflow steering, user confusion, and possible overshadowing of more suitable skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description defines applicability using a very wide set of themes and generic outcomes like needing a workflow, checklist, analysis, or implementation support. Such broad routing criteria increase the chance that unrelated requests are matched, causing misrouting and expanding the skill's effective authority beyond its intended scope.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt is extremely broad and loosely phrased, causing the skill to match a wide range of unrelated user requests. Combined with allow_implicit_invocation: true, this increases the chance the agent invokes the skill unexpectedly, which can lead to unintended prompt injection exposure, incorrect task routing, or inappropriate access to workflow context.

Vague Triggers

High
Confidence
88% confidence
Finding
The trigger sentence is written in broad, everyday language that can match many unrelated user requests, increasing the chance the skill activates outside its intended scope. Overbroad activation is dangerous because it can route users into an irrelevant workflow, suppress more appropriate tools, and create opportunities for prompt or policy confusion when adversarial users deliberately phrase requests to force invocation.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation examples are ambiguous and do not clearly separate in-scope requests from general requests, which makes accidental or adversarial triggering more likely. In a skill-selection system, unclear trigger scope can cause misrouting, unexpected execution paths, and unreliable behavior across adjacent skills competing for similar language.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.