Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation and workflow helper with no executable code, though its trigger wording is broad and may cause accidental activation.

Installers should be aware that this skill may activate for some generic productivity, graph, knowledge, or bug-fix requests. It appears safe as a workflow/documentation helper, but tighter trigger wording would make routing more predictable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentence is broad and natural-language-like, so it can match ordinary user requests that only loosely relate to the skill. In an agent ecosystem, this increases the chance of unintended skill activation, causing the model to apply the wrong workflow, expose irrelevant capabilities, or interfere with higher-priority safety or routing logic.

Vague Triggers

Medium
Confidence
94% confidence
Finding
This trigger phrase is ambiguous and framed as a generic request for a practical workflow, which makes accidental invocation likely across many unrelated productivity tasks. Because the skill is positioned for broad work-productivity use, ambiguous routing can misdirect user requests, create confusing agent behavior, and expand the effective attack surface for prompt/skill selection mistakes.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are generic and can match ordinary user requests such as asking for practical workflows, bug fixes, or hardening help. This can cause the skill to activate outside its intended scope, increasing the chance of unintended behavior, priority hijacking over more appropriate skills, or exposure to adversarial prompts that exploit the skill's broad routing surface.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description uses very broad activation terms like 'work-productivity,' 'analysis,' and 'implementation support,' which can cause the skill to activate for many unrelated user requests. In an agent-routing context, this can lead to incorrect skill selection, unintended instruction injection into unrelated tasks, and reduced reliability or safety controls because the skill operates outside its intended scope.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords include highly generic terms such as 'typed,' 'knowledge,' 'graph,' 'creating,' and 'bug fix,' which are common across many benign and unrelated tasks. These loose triggers materially increase the chance of overbroad activation and prompt hijacking at the routing layer, causing this skill to intercept requests it should not handle and potentially override more appropriate, safer skills.

Vague Triggers

High
Confidence
95% confidence
Finding
触发关键词包含 `typed`、`knowledge`、`graph`、`creating`、`bug fix` 等高频通用词,且缺少组合条件或排除规则,容易在大量无关对话中误触发该技能。误触发本身不一定直接造成代码执行风险,但会导致错误路由、无关指令注入上下文,并可能让后续代理流程偏离用户真实意图。

Vague Triggers

Medium
Confidence
88% confidence
Finding
技能描述中的适用范围覆盖 `work-productivity`, `ontology`, `typed`, `knowledge`, `graph` 以及“practical workflow/artifact/checklist/analysis/implementation support”等宽泛需求,但没有明确不适用场景或触发边界。这样的模糊范围会扩大技能匹配面,使系统在普通知识问答或一般生产力任务中也可能错误调用该技能。

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt contains broad, generic activation language tied to common concepts like work productivity, ontology, workflow, checklist, analysis, and implementation support. Combined with allow_implicit_invocation: true, this increases the chance the skill is invoked in situations the user did not clearly intend, which can cause prompt-scope confusion and unintended tool or skill routing.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentence is extremely broad and closely resembles normal user language, which can cause the skill to activate in contexts far beyond its intended scope. Over-broad activation creates routing confusion and increases the chance that unrelated requests are captured by this skill, potentially bypassing more appropriate or safer skills.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation examples do not clearly define when the skill should and should not fire, making invocation ambiguous. This ambiguity can lead to accidental activation, misrouting of user requests, and unpredictable behavior in agent workflows that depend on precise skill selection.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.