Back to skill

Security audit

Work Productivity Pollyreach Gives Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad auto-trigger wording, but it does not install code, access credentials, persist, or exfiltrate data.

Before installing, consider narrowing the trigger terms or disabling implicit invocation so this helper is selected only for explicit PollyReach-style workflow requests. The inspected artifact otherwise behaves like a low-risk documentation/workflow skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords and example trigger sentences are excessively broad and include common terms such as 'every', 'phone', 'number', 'ability', and 'things', which are likely to appear in unrelated conversations. This can cause unintended activation of the skill, leading the agent to route ordinary user requests into this workflow and potentially produce irrelevant or unsafe actions in the wrong context.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords and example invocations are overly broad and include common words such as "every," "phone," "number," "ability," and "things," which can cause the skill to activate for unrelated user requests. In an agent ecosystem, this can lead to unintended routing, prompt hijacking of normal tasks, and execution of workflows outside the user's intent, making the skill materially unsafe even though the content is not overtly malicious.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger list contains very common words such as "gives," "every," "phone," "number," "ability," and "things," which are likely to appear in unrelated user requests. This can cause unintended skill activation, routing ordinary conversations into this skill and increasing the chance of incorrect automation, irrelevant responses, or shadowing more appropriate skills.

Vague Triggers

High
Confidence
95% confidence
Finding
The description says to use the skill when a user asks for broad categories like "work-productivity" or needs a "practical workflow, artifact, checklist, analysis, or implementation support," which are generic request types rather than a narrow capability boundary. This ambiguous invocation condition makes the skill eligible for a wide range of unrelated prompts, creating misrouting risk and unreliable behavior.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger phrases use highly generic wording such as "Help me" and "I need a practical workflow," which overlaps heavily with normal user requests. These examples train or encourage broad activation behavior, making accidental invocation more likely even when the user is asking for something unrelated.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keyword list includes highly generic terms such as 'every', 'phone', 'number', 'ability', 'things', and 'done'. This can cause the skill to activate on unrelated user requests, leading to incorrect routing, unexpected behavior, and possible interference with other skills or user workflows.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says to use the skill for broad categories like work-productivity and for users needing general workflow or implementation support, but it does not clearly define boundaries for when this specific skill should be selected. Ambiguous activation criteria increase the chance of accidental invocation and misapplication of the skill in contexts it was not designed for.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The example trigger phrases begin with very common help-seeking language like 'Help me' and 'I need a practical workflow', which can overlap with ordinary user prompts. If matching logic relies on these patterns, the skill may be invoked for many unrelated requests, reducing routing precision and potentially overriding more appropriate skills.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt is broad and loosely phrased, which can cause the skill to be invoked for generic productivity-related requests without clear user intent. In a system that supports automatic routing, this increases the chance of accidental activation, context leakage to the wrong skill, and unexpected behavior that users did not explicitly request.

Vague Triggers

High
Confidence
97% confidence
Finding
Enabling implicit invocation without tight trigger boundaries allows the platform to auto-select this skill for loosely related requests. Because the skill description and prompt are broad, this significantly raises the risk of overbroad routing, unintended access to user context, and execution of the wrong workflow in sensitive work-productivity scenarios.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrase includes overly broad everyday language, which can cause the skill to activate for unrelated user requests. In an agent environment, ambiguous activation increases the chance of unintended workflow execution, context hijacking, or routing sensitive tasks to a skill that was not actually requested.

Vague Triggers

Medium
Confidence
89% confidence
Finding
Although some context is present, the trigger sentence still remains ambiguous and could match a wide range of ordinary productivity or support requests. This can lead to false invocation, confusing task routing, and accidental exposure of user context to a skill that is only loosely related to the actual request.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.