Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overbroad activation wording but no executable code, persistence, credential handling, or hidden data access.

Before installing, consider whether you want this skill to activate implicitly. Its behavior appears safe and purpose-aligned, but its broad trigger terms may make it appear for general productivity, knowledge, graph, or bug-fix requests where another skill might fit better.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad, natural-language sentences that could plausibly appear in ordinary user requests, increasing the chance the skill is invoked when the user did not explicitly intend it. In an agent ecosystem, unintended invocation can route tasks into the wrong workflow, causing mis-execution, confusion, or unsafe handling of requests that should have gone elsewhere.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad enough to match ordinary help requests about productivity, workflows, bug fixing, or hardening, which can cause the skill to activate outside its intended scope. That increases the chance of unintended prompt injection surface, user confusion, and misrouting of tasks to this skill when a more appropriate or safer skill should handle them.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description is extremely broad and maps to common concepts like work-productivity, knowledge, graph, analysis, and implementation support. This can cause the skill to activate for many unrelated user requests, increasing the chance it overrides more appropriate skills or injects unintended workflow guidance into normal conversations.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords include generic terms such as "typed," "knowledge," "graph," "structured," "memory," and "creating," which appear in many benign prompts. Such unconstrained keywords make accidental invocation likely and can broaden the skill's effective control surface far beyond its intended purpose.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger sentences use natural, everyday phrasing that resembles ordinary user requests rather than deliberate skill invocation. This increases the probability of unintended activation during routine conversations, which can confuse orchestration and cause irrelevant or lower-quality outputs.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords are overly broad and include generic terms like "typed", "knowledge", "graph", and "creating", which can overlap with many unrelated user requests. This can cause unintended skill activation, leading the agent to apply the wrong workflow, expose irrelevant instructions, or interfere with higher-priority task routing.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation while using a very broad description and default prompt that match generic productivity and help-seeking requests. This can cause the agent to invoke the skill in situations beyond the user's clear intent, expanding its influence over unrelated workflows and increasing the chance of prompt hijacking, misrouting, or unsafe task handling.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and partially mirror ordinary user requests such as asking for practical workflow help, bug fixes, or hardening. This can cause unintended activation of the skill in contexts where the user did not explicitly request this capability, increasing the chance of prompt routing errors, irrelevant skill execution, and accidental exposure of the skill's instructions in unrelated tasks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.