Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This documentation-only workflow helper does not show hidden execution or data access, though its trigger wording is broad and may activate more often than intended.

Install only if you want a general ontology-style workflow helper that may be invoked implicitly. Publishers should narrow the trigger keywords and examples to explicit ontology or typed-knowledge-graph workflow requests to reduce accidental activation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger examples are written as broad natural-language requests that closely resemble ordinary user speech, which can cause the skill to activate unintentionally in unrelated conversations. This increases the chance of misrouting user tasks, injecting irrelevant workflow behavior, and causing downstream agents to follow the wrong instructions without clear user intent.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation section does not define firm activation boundaries, so the skill may be selected for vague requests that partially match broad terms like 'help me' or 'I need a practical workflow.' In an agent ecosystem, ambiguous triggering can lead to overbroad skill invocation, unintended instruction precedence, and unreliable task execution.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and likely to match ordinary user requests unrelated to this specific skill. This can cause unintended activation or over-selection of the skill, leading to prompt-routing errors, user confusion, and possible invocation in contexts where the skill’s workflow or assumptions are inappropriate.

Vague Triggers

High
Confidence
98% confidence
Finding
The skill description is broad enough to match many ordinary productivity, workflow, knowledge, and implementation requests, which can cause this skill to activate outside its intended niche. Over-broad routing increases the chance that unrelated user tasks are handled by the wrong skill, leading to prompt-scope confusion, unreliable behavior, and possible interception of tasks meant for more constrained or safer skills.

Vague Triggers

High
Confidence
99% confidence
Finding
The keyword triggers include highly generic terms such as 'knowledge', 'graph', 'structured', 'memory', 'creating', and 'bug fix', all of which are common across many unrelated requests. This makes accidental or excessive activation likely, which can undermine skill selection integrity and create a broad prompt-injection or task-hijacking surface in multi-skill environments.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The example trigger sentences are themselves vague and mostly restate broad user needs without defining clear boundaries for when the skill should or should not activate. Ambiguous examples train operators and routing logic toward overmatching, reinforcing accidental invocation and reducing confidence that the skill is handling only intended ontology-specific workflows.

Vague Triggers

Medium
Confidence
88% confidence
Finding
触发关键词包含非常通用的词,如“typed”“knowledge”“graph”“creating”“bug fix”,且示例触发句也较宽泛,容易让技能在与本技能目标无关的普通任务中被误触发。被错误启用后,代理可能应用不适配的流程或输出模板,造成任务偏航、错误建议,甚至绕过更合适的专用技能。

Vague Triggers

Medium
Confidence
84% confidence
Finding
技能描述强调需求广泛,但没有清楚定义边界、排除条件和优先级规则,导致启用范围过宽。对于代理系统而言,这类模糊激活标准会增加上下文污染和错误路由风险,使模型在不适合的场景中调用该技能并产出不可靠结果。

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt is broadly phrased and tied to a wide set of loosely related concepts, which can cause the skill to activate in contexts the user did not clearly intend. Because implicit invocation is enabled, this increases the chance of accidental routing, prompt-scope expansion, and unintended disclosure or manipulation within unrelated tasks.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is broad enough to match ordinary user phrasing about getting help or needing a workflow, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of inappropriate routing, context confusion, and accidental invocation of a skill in situations where a more specific or safer skill should handle the request.

Vague Triggers

Medium
Confidence
91% confidence
Finding
This trigger is ambiguous because it does not clearly define when the skill should activate versus when a general planning or productivity skill should respond. In agent systems, ambiguous routing conditions can be exploited indirectly by causing misfires, over-selection of this skill, or degraded reliability of skill orchestration.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.