Back to skill

Security audit

Work Productivity Pollyreach Gives Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation terms but no hidden execution, credential access, persistence, or destructive behavior.

Before installing, consider narrowing the trigger keywords and disabling implicit invocation unless you specifically want this helper to activate for broad productivity or PollyReach-style workflow requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger sentences are extremely broad and partially generic, causing the skill to match ordinary user requests that are not specifically asking for this skill. In an agent-routing system, this can lead to unintended activation, prompt hijacking of unrelated tasks, and unsafe overreach where the skill influences workflows beyond its intended scope.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The keyword list includes very common terms like 'every', 'phone', 'number', 'ability', 'things', and 'done', which are likely to appear in unrelated conversations. This makes accidental invocation likely and increases the chance that the skill will intercept or shape tasks it was never meant to handle.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad, generic request templates that can match ordinary user language unrelated to this specific skill. This creates a real risk of unintended invocation, causing the agent to activate the wrong workflow, which can confuse users, misroute tasks, or apply inappropriate automation in normal conversations.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The keyword list includes extremely common terms such as 'every', 'phone', 'number', 'ability', 'things', and 'done', which are likely to appear in unrelated conversations. Overly broad activation keywords increase the chance that this skill is selected when not intended, leading to unreliable routing and possible interference with more appropriate skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger list includes extremely generic everyday terms like "every," "phone," "number," "ability," "things," and "done," which can cause the skill to activate for many unrelated user requests. Overbroad invocation increases the chance that this skill overrides more appropriate skills or injects irrelevant workflow behavior into unrelated tasks, reducing reliability and potentially creating unsafe cross-context assistance.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description says to use the skill when a user asks for broad categories like "work-productivity" or simply "needs a practical workflow, artifact, checklist, analysis, or implementation support," which is far too expansive. This ambiguity can cause unintended routing to this skill for many generic productivity or implementation requests, making system behavior unpredictable and easier to manipulate through prompt phrasing.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences are built from generic phrasing like "Help me" and "I need a practical workflow," without clear boundaries separating this skill from ordinary user requests. Such examples encourage accidental invocation patterns and make it easier for unrelated prompts to match the skill, amplifying misrouting risk.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords include extremely broad everyday terms such as “every”, “phone”, “number”, “ability”, “things”, and “done”, which can match many unrelated user requests. This creates a real overbroad-trigger vulnerability: the skill may activate outside its intended scope, causing unintended routing, prompt contamination, or interference with more appropriate skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description says it should be used when users mention broad categories like work-productivity, pollyreach, gives, every, or phone, or when they need a practical workflow or checklist around the requirement. This activation guidance is vague and weakly bounded, making it easy for unrelated requests to satisfy the condition and trigger the skill unexpectedly.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The example trigger sentences are highly generic and encourage invocation from broad phrases like “I need a practical workflow...” without enough domain specificity. These examples can train downstream routing behavior toward over-triggering, increasing accidental activation and reducing skill-selection reliability.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt and skill description use very broad, common trigger terms like 'help me', 'workflow', 'checklist', and generic productivity language, while implicit invocation is enabled. This can cause the skill to be selected in contexts far beyond its intended scope, increasing the chance of unintended prompt injection exposure, inappropriate tool use, or user confusion from unsolicited activation.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger content includes extremely generic terms and phrasing such as 'every', 'phone', 'number', and 'things done', which can match ordinary user requests unrelated to this skill. Overbroad activation increases the chance the agent will invoke the skill in unintended contexts, causing prompt-routing errors, irrelevant workflow execution, and possible exposure of user context to a skill that was not actually requested.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation examples are ambiguous and use broad natural-language phrasing like 'Help me' and 'I need a practical workflow' followed by truncated requirement text, without clearly delimiting when this specific skill should activate. This can cause accidental or adversarial skill selection, especially in systems that rely on semantic matching, leading to misrouting and unpredictable behavior across unrelated tasks.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.