Back to skill

Security audit

Work Productivity Pollyreach Gives Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation terms but no hidden execution, credential access, persistence, or destructive behavior.

Installers should be aware this skill may activate too easily on unrelated productivity or phone/number-related requests. It appears safe as a documentation helper, but its trigger keywords should be narrowed before relying on automatic routing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and include common words such as 'phone', 'number', 'ability', 'things', and 'done', which can cause the skill to activate for unrelated everyday requests. In an agent ecosystem, this increases the risk of unintended invocation, prompt-routing mistakes, and inappropriate handling of user tasks under the wrong workflow, which can degrade safety and reliability.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match common, unrelated user requests, which can cause the skill to activate outside its intended scope. In an agent environment, this can misroute tasks, confuse users, and increase the chance that the skill handles sensitive or irrelevant workflows without clear user intent.

Vague Triggers

High
Confidence
95% confidence
Finding
The manifest description uses very broad terms such as 'work-productivity,' 'practical workflow,' 'artifact,' 'checklist,' and 'analysis,' which can match many unrelated user requests. This increases the chance the skill is invoked outside its intended scope, causing unintended behavior, unsafe context switching, or interference with more appropriate skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes highly generic words like 'every,' 'phone,' 'number,' 'ability,' 'things,' and 'done,' which are common in ordinary conversation and unrelated tasks. Such vague triggers can cause widespread accidental activation, reducing routing precision and potentially exposing users to irrelevant or unsafe automation behavior.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example triggers are framed with broad phrases like 'Help me' and 'I need,' then append a long generic requirement statement instead of demonstrating precise activation boundaries. This encourages overly permissive matching behavior and makes it difficult to distinguish intentional invocation from normal user help requests.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keyword list includes extremely broad everyday terms such as "every", "phone", "number", "ability", "things", and "done", which can cause the skill to activate for many unrelated user requests. In an agent-routing context, this creates misrouting risk, unintended invocation, and potential exposure of the user to irrelevant or unsafe workflow guidance when another skill should have handled the request.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description states that it should be used when users mention broad categories like work-productivity or need almost any practical workflow, checklist, analysis, or implementation support for the requirement. This trigger condition is too open-ended, making the skill eligible for a wide range of unrelated tasks and increasing the chance of incorrect routing or overbroad delegation.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt uses very broad trigger language such as generic requests for help with workflows, artifacts, checklists, analysis, or implementation support. Combined with implicit invocation, this can cause the skill to activate on ordinary user requests outside its intended scope, creating prompt-routing confusion and increasing the chance that unrelated tasks are influenced by this skill's instructions.

Vague Triggers

High
Confidence
90% confidence
Finding
The trigger sentence is excessively broad and malformed, making it likely to activate on vague user requests that are not clearly about this skill’s intended scope. Overbroad routing conditions can cause inappropriate skill invocation, increasing the chance of unintended task handling, prompt-scope confusion, or chaining into workflows the user did not explicitly request.

Vague Triggers

Medium
Confidence
85% confidence
Finding
This trigger is broadly phrased and lacks clear boundaries, so it may match many generic requests for a 'practical workflow' even when unrelated to the documented requirement. In an agent system, ambiguous activation logic can misroute requests, expose users to irrelevant automation, and reduce assurance that the selected skill is appropriate and safe for the context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.