Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with broad activation wording but no hidden execution, data access, persistence, or destructive behavior.

Before installing, be aware that this skill may trigger on broad productivity or knowledge-work prompts. Install it if you want a general ontology/workflow planning helper, but prefer explicit invocation by skill name for unrelated tasks so it does not steer ordinary requests into this workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and include common help-seeking language, which increases the chance that the skill will be invoked unintentionally during unrelated user requests. In an agent ecosystem, accidental invocation can route tasks into the wrong workflow, causing confusion, incorrect outputs, or unintended access to the skill’s behavior surface.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match common, non-specialized requests, which can cause the skill to activate outside its intended scope. In an agent environment, overbroad invocation increases the chance of prompt/context hijacking, inappropriate workflow execution, or accidental use on tasks the skill was not designed to handle.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description is very broad and includes generic categories like work-productivity, knowledge, graph, and implementation support, which can cause the skill to activate for many unrelated user requests. Over-broad activation can route users into an unintended workflow, producing irrelevant guidance, masking more appropriate skills, or causing unsafe assumptions in contexts involving setup or safety hardening.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger keywords include highly generic terms such as typed, knowledge, graph, structured, memory, creating, and bug fix, which are common across many unrelated tasks. This makes accidental invocation likely, increasing the chance of misrouting, low-quality assistance, or inappropriate application of workflow guidance in contexts the skill was not designed to handle.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger keywords are broad and generic (for example, terms like "knowledge", "graph", "structured", and "creating"), which can cause the skill to activate for many unrelated user requests. In an agent routing context, this can misdirect tasks, override better-matched skills, and produce irrelevant or misleading assistance, reducing reliability and potentially interfering with safety-sensitive workflows.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation condition in the description is ambiguous because it mixes broad topical words with vague requests for "practical workflow, artifact, checklist, analysis, or implementation support." This makes it unclear when the skill is appropriate, increasing the chance of accidental invocation and incorrect delegation by upstream agent selection logic.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill enables implicit invocation but does not define a narrow, well-bounded trigger condition in the visible configuration. That makes it easier for the platform to auto-select this skill for broad prompts involving productivity, workflows, knowledge, or analysis, increasing the chance of unintended execution, context leakage, or the skill influencing tasks outside its intended scope.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger examples are broad, natural-language phrases that can match many unrelated user requests, increasing the chance this skill activates outside its intended scope. In an agent ecosystem, overbroad activation can route sensitive or irrelevant tasks into a workflow that makes assumptions and proceeds with limited clarification, which can cause incorrect actions, data handling mistakes, or user confusion.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation guidance defines keywords and trigger sentences without clear boundaries, so the skill may be invoked for generic work-productivity, knowledge, graph, or bug-fix prompts that only loosely relate to the requirement. This creates an authorization and reliability risk in agent selection: the wrong skill can be chosen, producing overconfident but mis-scoped outputs and potentially exposing context to an unnecessary workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.