Back to skill

Security audit

Work Productivity Pollyreach Gives Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper, but its trigger rules are broad enough that it could be invoked for unrelated requests.

Review this skill before installing if your agent uses implicit skill routing. The main risk is not malicious code, but that ordinary requests involving words like phone, number, done, or practical workflow may route into this helper unexpectedly. Narrowing the trigger phrases to explicit PollyReach-style workflow requests would reduce that risk.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases and keywords are broad, generic, and partially malformed, which increases the chance that the skill will be invoked for unrelated requests. In an agent environment, unintended invocation can cause workflow confusion, misrouting, or execution of the wrong skill in contexts where different safeguards or capabilities were expected.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords and example phrases are extremely broad, including common terms like work-productivity, phone, number, ability, things, and done. This can cause the skill to activate for unrelated everyday requests, leading to unintended routing, prompt hijacking of normal user tasks, and unsafe overreach into contexts the user did not intend.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes extremely generic terms such as "every," "phone," "number," "ability," "things," and "done," which can match large volumes of unrelated user requests. This can cause the skill to activate outside its intended scope, leading to prompt hijacking of routing behavior, user confusion, and unsafe delegation to an irrelevant workflow.

Vague Triggers

High
Confidence
92% confidence
Finding
The manifest description says to use the skill when a user asks for broad terms like work-productivity or practical workflow support, which are common across many unrelated tasks. This ambiguous activation condition increases the chance the orchestrator will invoke the skill inappropriately, expanding its authority beyond the intended PollyReach-style use case.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger sentences are truncated, malformed, and fail to show clear boundaries for when the skill should or should not activate. Poor examples can train users or routing systems toward overbroad matching, reinforcing accidental invocation and reducing confidence in skill selection safety.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keyword list includes extremely broad everyday terms such as 'every', 'phone', 'number', 'ability', 'things', and 'done', which can cause accidental invocation in many unrelated conversations. In an agent-routing context, overbroad triggers can misroute user requests, inject irrelevant workflow behavior, and suppress selection of more appropriate skills, reducing safety and reliability.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description defines activation conditions in very broad, weakly bounded language, allowing it to match a wide range of requests for 'practical workflow, artifact, checklist, analysis, or implementation support.' This ambiguity increases the chance that the system selects the skill outside its intended scope, which can lead to incorrect assistance, prompt-routing conflicts, and degraded trust in agent behavior.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The example trigger phrases are highly generic and effectively restate the broad demand statement rather than demonstrating precise invocation boundaries. This can train authors or routing logic to treat vague requests as valid triggers, increasing false activations and reducing predictability of skill selection.

Vague Triggers

High
Confidence
95% confidence
Finding
The default prompt includes broad, common-language trigger terms like "help me" and generic workflow/productivity phrasing, which can cause the skill to activate in ordinary user conversations unrelated to the intended task. Because implicit invocation is enabled, this increases the risk of accidental routing, prompt hijacking opportunities, and unintended execution in contexts where the user did not mean to invoke this skill.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords and sample phrases are overly broad and include common words like "gives," "every," "phone," and "things done," which can cause this skill to activate for unrelated user requests. In an agent-routing system, that creates misfires and prompt-scope capture, where the wrong skill handles inputs it was not intended for, potentially displacing safer or more relevant skills.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.