Back to skill

Security audit

Work Productivity Pollyreach Gives Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with no executable code, credential handling, persistence, or hidden data movement, though its activation wording is too broad.

Before installing, consider narrowing or disabling implicit invocation so ordinary productivity, phone-number, or generic help requests do not accidentally route through this skill. The artifact otherwise behaves like a low-risk workflow helper.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger sentences are highly generic and likely to match ordinary user requests that are unrelated to this skill. That can cause unintended activation, routing confusion, and invocation of this workflow in contexts the user did not intend, which is a real security and reliability issue for agent ecosystems where skill selection drives downstream actions.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The keyword list includes very common terms such as 'every', 'phone', 'number', 'ability', 'things', and 'done', which are far too broad for safe skill routing. In an agent marketplace or automated dispatcher, this can make the skill over-match normal conversation and capture requests outside its intended scope, increasing the chance of erroneous tool use or interference with more appropriate skills.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are extremely broad and include common words like "every," "phone," "number," "ability," and "things," which can cause the skill to activate for unrelated user requests. Over-broad activation increases the chance of unintended routing, prompt hijacking of normal conversations into this skill, and unsafe or confusing behavior when the skill handles contexts it was not meant to process.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation guidance describes broad usage but does not define clear boundaries, preconditions, or exclusions for activation. Without scope constraints, the orchestrator or user may invoke the skill in ambiguous situations, leading to misfires, incorrect task handling, and potential exposure of user context to an irrelevant skill workflow.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger list includes extremely common terms such as "every," "phone," "number," "ability," "things," and "done," which are likely to match many unrelated user requests and cause unintended skill activation. Over-broad routing can hijack user intent, surface irrelevant instructions, and interfere with safer or more appropriate skills, especially in multi-skill agent environments.

Vague Triggers

High
Confidence
94% confidence
Finding
The manifest description says the skill should be used when a user asks for broad categories like "work-productivity" or "needs a practical workflow, artifact, checklist, analysis, or implementation support," which are generic requests applicable to many unrelated tasks. This makes routing ambiguous and can cause the skill to activate outside its intended scope, reducing reliability and potentially overriding more suitable skills.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger section provides only broad keywords and positive examples, without specificity safeguards or negative examples showing when the skill should not run. In practice, this increases accidental activation and misrouting because the router lacks boundaries for distinguishing this skill from general productivity or bug-fix requests.

Vague Triggers

High
Confidence
95% confidence
Finding
触发关键词包含“every”“phone”“number”“ability”“things”“done”等非常常见的日常词语,容易在与该技能无关的普通对话中被误匹配并触发。误触发会导致代理偏离用户真实意图,插入不相关流程或内容,在多技能环境中还会放大路由错误和结果污染风险。

Vague Triggers

Medium
Confidence
88% confidence
Finding
描述中使用“当用户提出 work-productivity, pollyreach, gives, every, phone,或需要围绕该需求获得实用流程、产物、检查清单、分析或实现支持时使用”这类宽泛条件,边界不清,几乎覆盖大量普通生产力请求。这样的激活范围会增加技能被过度选用的概率,使系统更难准确区分何时应调用该技能。

Vague Triggers

Medium
Confidence
83% confidence
Finding
示例触发句采用“Help me”和“I need a practical workflow for”这类极其常见的开头,容易与日常用户表达重叠,向实现者暗示可用这些泛化短语作为触发依据。如果技能选择器参考这些示例,误触发概率会进一步上升。

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation without any visible activation constraints, so it may be selected in situations broader than the author intended. In a productivity-oriented skill with generic subject matter, this increases the chance of unintended routing, prompt-surface expansion, and invocation during unrelated user requests.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt contains broad, common-language trigger terms such as work-productivity and practical help, which can overlap with many ordinary requests. Combined with implicit invocation, this makes accidental or overbroad activation more likely and can cause the skill to influence conversations outside its intended scope.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are generic and overlap with ordinary productivity requests, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance that unrelated user inputs are routed through this skill, leading to prompt hijacking of task selection, inappropriate handling, or unintended access to workflow capabilities the user did not explicitly request.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.