Back to skill

Security audit

Work Productivity Pollyreach Gives Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a low-impact workflow helper, but its broad activation wording may make it show up for unrelated productivity requests.

Before installing, consider narrowing or disabling implicit activation if you only want this skill for explicit PollyReach or workflow-hardening requests. The inspected artifacts do not show hidden execution, credential access, persistence, or exfiltration behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentences are extremely broad and include generic phrasing that could match ordinary user requests unrelated to this skill. That increases the chance of unintended auto-invocation, causing the wrong skill to run, confusing users, and potentially applying workflow actions in inappropriate contexts.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The keyword list contains highly generic terms like 'every', 'phone', 'number', 'ability', 'things', and 'done', which are common in everyday prompts. In a skill-routing system, such nonspecific keywords can cause excessive matching and unintended invocation far outside the intended scope.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad and include generic terms like work-productivity, phone, number, ability, things, and done, which can cause the skill to activate for unrelated everyday requests. In an agent ecosystem, overbroad activation can route benign user prompts into the wrong workflow, causing unintended actions, user confusion, or unsafe handling if the skill later performs automation based on mistaken invocation.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keyword list includes extremely common words such as "gives," "every," "phone," "number," "ability," "things," and "done," which can cause the skill to activate in many unrelated conversations. This creates unintended invocation risk, leading to incorrect routing, prompt-scope confusion, and possible interference with other skills or tasks.

Vague Triggers

High
Confidence
95% confidence
Finding
The example trigger phrases rely on generic language like "Help me" and "I need," making the skill appear eligible for ordinary user requests that have nothing to do with this workflow. In a routing system, such vague examples can bias matching toward accidental invocation, reducing reliability and potentially causing the wrong skill to handle sensitive or important tasks.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keyword list includes extremely broad everyday terms such as “every”, “phone”, “number”, “ability”, “things”, and “done”, which can match many unrelated user requests. This can cause the skill to activate outside its intended scope, creating prompt-routing confusion and increasing the chance that users receive irrelevant or unsafe workflow guidance in the wrong context.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description says it should be used when users mention broad categories like work-productivity or need any practical workflow, checklist, analysis, or implementation support for this requirement. That activation boundary is too vague, so the system may over-select this skill for many ordinary productivity or support requests that do not actually relate to the intended PollyReach-style workflow use case.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger phrases are phrased as generic help requests like “Help me...” and “I need a practical workflow...”, which resemble normal user queries across many domains. These examples reinforce broad matching behavior and may train routing logic or maintainers to treat ordinary support language as sufficient to invoke the skill.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The skill enables implicit invocation while providing only a broad productivity-oriented description, so the platform may trigger it from loosely related user requests. This increases the chance of accidental activation, causing the skill to run outside the user's clear intent and potentially influence responses or workflows unexpectedly.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The default prompt uses generic language such as 'help me' alongside broad workflow terms, which can overlap heavily with normal user phrasing. When combined with implicit invocation, this creates a meaningful risk that ordinary conversations will unintentionally match and activate the skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad and include common terms such as "help me," "practical workflow," and generic productivity language, which can cause the skill to activate for unrelated requests. This increases the chance of unintended invocation, confusing routing, and accidental application of the skill in contexts the user did not intend.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.