Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a prompt-only workflow helper with overly broad activation wording, but no hidden execution, persistence, credential access, or data exfiltration behavior was found.

Before installing, consider whether you want this skill to be implicitly selected for broad workflow, knowledge-graph, or bug-fix requests. It appears prompt-only and proportionate, but narrower trigger wording would reduce accidental activation in unrelated conversations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger sentence is extremely broad and maps to common user phrasing like 'help me' or 'I need a practical workflow,' which can cause the skill to activate outside its intended niche. Overbroad activation increases the chance of prompt-scope hijacking, inappropriate routing, or accidental invocation on unrelated tasks, especially in shared agent environments.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The activation guidance provides keywords and trigger examples but does not define boundaries, exclusions, or prerequisite conditions for invocation. Without scope constraints, an orchestrator or agent may over-select this skill for generic productivity or implementation requests, leading to unintended behavior and possible interference with safer or more appropriate skills.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad enough to match common user requests about workflows, productivity, ontology, or bug-fixing, which increases the chance of accidental or overly eager invocation. In an agent ecosystem, unintended invocation can cause the wrong skill to steer task execution, creating confusing behavior, privilege overreach within the agent’s allowed scope, or unsafe automation chaining.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description is broad enough to match many ordinary requests about productivity, knowledge, workflows, or implementation help, which can cause unintended invocation. Over-broad routing increases the chance that this skill intercepts prompts outside its intended scope, leading to confusing behavior, policy bypass through misrouting, or overshadowing more appropriate specialized skills.

Vague Triggers

High
Confidence
97% confidence
Finding
The keyword list includes generic terms such as "knowledge," "graph," "structured," "creating," and "bug fix," which are common across many unrelated requests. In a skill-selection system, such vague triggers can cause excessive activation overlap and accidental capture of broad user traffic, making routing unreliable and potentially suppressing safer or more relevant skills.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example triggers use highly generic lead-ins like "Help me" and "I need a practical workflow," which teach the matcher that ordinary phrasing is sufficient for activation. This broadens the effective trigger surface and can increase false-positive invocation rates, especially when combined with the already-generic description and keyword list.

Vague Triggers

Medium
Confidence
91% confidence
Finding
触发关键词列表包含较宽泛且常见的词,如“typed”“knowledge”“graph”“creating”“bug fix”。这会让技能在与该技能真实目标无关的普通对话中被意外匹配,导致错误激活、上下文污染,甚至把用户带入不适当的工作流。

Vague Triggers

Medium
Confidence
88% confidence
Finding
示例触发句采用“Help me”“I need a practical workflow for”“Use $skill to handle”这类高度通用的开头,但后续需求边界定义仍然模糊。若系统把示例句作为触发参考,可能扩大匹配面,造成误调用、用户意图识别偏差,并在多技能环境中干扰更合适技能的选择。

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation without any visible trigger constraints or narrowing conditions, so the platform may auto-select it for loosely related requests. Because the skill is framed around broad productivity and workflow help, unintended activation could cause the agent to inject this skill's behavior into unrelated conversations, increasing prompt-scope confusion and the chance of unsafe or incorrect task execution.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt uses very broad, everyday language such as helping with productivity, workflows, artifacts, checklists, analysis, and implementation support. This overlaps with many normal user requests, so combined with implicit invocation it raises the likelihood of accidental routing, hidden prompt injection into ordinary sessions, and skill execution outside its intended context.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is broad and generic enough that ordinary user requests about workflows, help, or productivity could invoke this skill unintentionally. That can cause inappropriate routing, context hijacking, or the skill being selected when a more specific and safer skill should handle the request, reducing reliability and potentially exposing downstream workflows to unintended behavior.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation guidance lacks precise boundaries and relies on ambiguous examples, making the skill prone to over-triggering across unrelated requests. In an agent ecosystem, ambiguous invocation logic can lead to misrouting, accidental execution of the wrong workflow, and erosion of trust in routing and safety controls.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.