Back to skill

Security audit

Work Productivity Pollyreach Gives Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with no executable code or credential access, though its activation terms are too broad.

Install only if you want a broad PollyReach-style workflow helper. The main practical risk is accidental activation on unrelated requests because the trigger metadata is loose; narrowing triggers to PollyReach-specific workflow, reliability, or hardening requests would make it cleaner.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentences are so generic that they can match ordinary user requests unrelated to this skill, causing the skill to activate unexpectedly and potentially override more appropriate workflows. In an agent ecosystem, broad auto-triggering increases the chance of misrouting user tasks, prompt-scope confusion, and unintended execution of this skill in contexts where its instructions do not fit.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The keyword list includes highly generic terms such as "every," "phone," "number," "ability," and "things," which are common in everyday conversation and create excessive trigger surface. This makes accidental activation likely and can let the skill capture unrelated requests, reducing routing integrity and making downstream agent behavior less predictable.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are extremely generic, including common terms like 'phone', 'number', 'ability', and 'things', which can cause the skill to activate for many unrelated user requests. In an agent-routing system, this increases the chance of unintended invocation, misrouting, and unsafe execution of workflows outside the user’s intended context.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes extremely common words such as "every," "phone," "number," "ability," "things," and "done," which can cause the skill to activate during unrelated ordinary conversations. This creates prompt-routing confusion and increases the chance that the skill intercepts requests it was never meant to handle, potentially degrading safety boundaries and causing unintended behavior across many contexts.

Vague Triggers

High
Confidence
92% confidence
Finding
The description says to use the skill when a user asks for broad categories like work-productivity or any practical workflow, artifact, checklist, analysis, or implementation support, which overlaps heavily with general-purpose assistance. Such vague invocation scope makes the skill hard to distinguish from unrelated helpers and raises the likelihood of incorrect routing into this skill.

Vague Triggers

High
Confidence
98% confidence
Finding
The example trigger sentences begin with phrases like "Help me" and "I need a practical workflow," which are common in everyday user requests and therefore highly collision-prone. Including these as examples teaches overly permissive activation patterns that can make the skill fire for many unrelated prompts, undermining reliable skill selection and potentially bypassing more appropriate routing safeguards.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keyword list includes very generic terms such as "every", "phone", "number", "ability", "things", and "done", which can cause the skill to activate in many unrelated conversations. This creates prompt-routing confusion and increases the chance that the agent invokes this skill unexpectedly, potentially displacing more appropriate skills or causing unsafe automation in the wrong context.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger phrases are broad and loosely formed, so they do not establish clear activation boundaries for when this skill should run. Ambiguous examples train the router or operator to over-apply the skill, which can lead to accidental invocation and reduced reliability of the overall agent system.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The skill enables allow_implicit_invocation without any activation constraints, which means the platform may auto-select this skill during ordinary conversations even when the user did not clearly intend to invoke it. Because the skill is framed around broad workflow help, this increases the chance of unintended routing, prompt-surface expansion, and accidental execution in contexts where the skill is not appropriate.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt uses very broad language such as 'help me' and generic productivity/workflow wording, which can overlap heavily with normal user requests. In combination with implicit invocation, this makes the skill easier to trigger unintentionally and can cause the system to apply this skill to unrelated prompts, degrading safety boundaries and increasing the chance of misrouting.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is so broad and generic that it can match ordinary user language unrelated to this skill’s intended scope, causing unintended invocation. In an agent environment, overbroad routing can expose the skill in contexts where it may produce irrelevant actions, interfere with higher-priority workflows, or increase the chance of unsafe automation being applied to the wrong task.

Vague Triggers

Medium
Confidence
89% confidence
Finding
This trigger is ambiguous because it does not clearly define what user request should activate the skill or what boundaries apply. Ambiguous activation increases misrouting risk, which is especially problematic for a broadly applicable productivity skill that could be invoked in many unrelated conversations and produce misleading or unnecessary workflow output.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.