Back to skill

Security audit

Work Productivity Ontology Typed Workflow Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only workflow helper with broad auto-invocation wording, but it does not install code, persist, access credentials, or perform hidden actions.

Installers should be aware that this skill may be selected too often because its triggers are broad and implicit invocation is enabled. It is otherwise a low-risk documentation/workflow helper; prefer explicit invocation when you want ontology-style workflow support.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description contains very broad activation criteria such as generic domains and common task types, which can cause the skill to trigger for many unrelated user requests. Over-broad routing increases the chance that this skill intercepts prompts outside its intended scope, leading to misapplication, prompt-surface expansion, and unsafe or low-quality behavior in agent orchestration.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger keyword list includes ambiguous, high-frequency terms like 'knowledge', 'graph', 'structured', 'creating', and 'bug fix' without guardrails. In an agent system, such generic triggers can cause accidental invocation across many normal conversations, making routing unreliable and potentially exposing users to unintended instructions or outputs from the wrong skill.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger guidance includes a highly generic phrase structure ('Help me ...', 'I need ...') tied to a broad requirement statement rather than narrowly scoped activation conditions. This can cause unintended invocation in unrelated conversations, leading the agent to apply the skill outside its intended context and potentially override more appropriate workflows or inject irrelevant operational guidance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger sentences are broad, natural-language phrases that overlap with ordinary user requests, which can cause the skill to activate unintentionally outside a clearly scoped invocation path. In an agent ecosystem, accidental invocation can route tasks into the wrong workflow, leading to inappropriate handling of user data, unexpected actions, or bypass of safer/more specific skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad, generic, and partly composed of natural-language requests a normal user might say, which can cause accidental invocation outside the author's intended scope. In an agent ecosystem, unintended routing can expose unrelated user requests to the wrong skill, leading to confused behavior, inappropriate task handling, or bypass of more suitable guarded workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example trigger sentences model vague invocation patterns that restate broad marketing language instead of bounded operational criteria. This can train maintainers or routing systems to invoke the skill on weak matches, amplifying the overreach created by the broad description and keyword set.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description says to use the skill whenever users mention broad domains or need almost any practical workflow, checklist, analysis, or implementation support related to the requirement. This ambiguous activation scope makes the skill eligible for a wide range of normal requests, increasing accidental invocation and making agent behavior less predictable and easier to misroute.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger keywords are very broad and include generic terms like "knowledge", "graph", "structured", "memory", and "creating", which are common in ordinary user prompts. This can cause the skill to activate unintentionally, leading to prompt-routing confusion, irrelevant automation, or overshadowing of more appropriate skills; while not code-execution dangerous, it weakens control boundaries and reliability.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill enables implicit invocation, but the metadata does not define a narrow, well-bounded trigger context. This can cause the agent to auto-select the skill in loosely related situations, expanding its authority and increasing the chance of unintended execution, prompt-scope confusion, or abuse through crafted user phrasing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation section does not clearly define where this skill applies versus where it should defer, and it mixes broad keywords ('knowledge', 'structured', 'creating', 'bug fix') with expansive trigger sentences. In an agent-routing context, ambiguous scope increases the chance of false activations, causing workflow confusion, misrouting, and accidental use of this skill in contexts with different safety or correctness requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This zh-CN README contains substantial English instructional content and trigger text, but does not state whether users may interact in Chinese or English or why English is required. That can create an implicit language constraint without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.