Back to skill

Security audit

Work Productivity Pollyreach Gives Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with no executable code, but its activation wording is overly broad and could make it appear for unrelated requests.

Install only if you want a general PollyReach-style workflow helper, and consider narrowing or disabling implicit triggers so ordinary productivity requests are not routed to this skill unexpectedly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger sentences are extremely broad and include generic phrasing such as 'Help me' and 'I need a practical workflow', which can cause the skill to activate for many unrelated user requests. In an agent ecosystem, this creates skill-hijacking and unintended invocation risk, where this skill may intercept prompts outside its intended scope and influence downstream behavior unexpectedly.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The keyword list contains broad everyday terms like 'every', 'phone', 'number', 'ability', and 'things', which are common across unrelated conversations. This significantly widens the activation surface and increases the likelihood of accidental matching, causing the skill to be selected in contexts where it is irrelevant and potentially disruptive.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests rather than a narrowly scoped skill invocation, which can cause unintended activation of this skill in unrelated conversations. In an agent ecosystem, overbroad activation can route users into the wrong workflow, create unsafe automation chains, and increase the chance that downstream actions are taken without clear user intent.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The keyword list contains highly generic terms like 'every', 'phone', 'number', and 'bug fix', which are likely to appear in many benign conversations and can spuriously activate the skill. This weakens intent matching and creates a prompt-routing vulnerability where unrelated requests may be handled by a workflow not meant for them.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords include extremely common terms such as "every," "phone," "number," "ability," and "done," which can cause the skill to activate for unrelated user requests. Overbroad activation creates prompt-scope hijacking risk, where this skill may intercept conversations outside its intended domain and steer behavior unexpectedly.

Vague Triggers

High
Confidence
92% confidence
Finding
The manifest description says to use the skill when a user asks for very broad concepts like "work-productivity" or needs a "practical workflow, artifact, checklist, analysis, or implementation support," which matches a huge range of benign requests. This ambiguity can cause unjustified invocation and make the skill a catch-all router, increasing the chance of irrelevant or unsafe task interception.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger phrases are generic requests for help with a workflow and do not clearly distinguish this skill from many unrelated tasks. Weak examples reinforce overbroad routing behavior and make it more likely that orchestration systems or authors will invoke the skill in contexts it was not designed to handle.

Vague Triggers

High
Confidence
97% confidence
Finding
触发关键词包含 `every`、`phone`、`number`、`ability`、`things`、`done` 等高频日常词汇,会显著扩大技能的匹配面,导致与本技能无关的普通请求被误触发。误触发后,代理可能在错误上下文中套用该工作流,造成响应偏题、越权介入任务流程,或掩盖本应由更合适技能处理的请求。

Vague Triggers

Medium
Confidence
91% confidence
Finding
技能描述把激活条件定义为用户提出 `work-productivity, pollyreach, gives, every, phone` 或需要“实用流程、产物、检查清单、分析或实现支持”时使用,这种范围过宽且边界模糊。由于后半部分几乎适用于大量普通生产力请求,路由器容易将不相关任务错误归入该技能,降低控制精度并增加意外执行不恰当流程的风险。

Vague Triggers

Medium
Confidence
88% confidence
Finding
示例触发句使用了 `Help me`、`I need a practical workflow for` 这类极通用表达,只在后面拼接需求文本,未展示清晰的触发边界。此类示例会误导调用方或自动路由系统把广泛的普通协助请求视为本技能适用场景,进一步放大误触发问题。

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt includes a very broad invocation phrase and generic terms like "help me" and references to common work-productivity concepts, which can cause accidental or implicit triggering in normal user conversation. Because implicit invocation is enabled, this increases the chance the skill activates outside clear user intent, potentially injecting unintended workflow behavior or exposing users to responses from an unrequested skill.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentence is overly broad and uses everyday-language phrasing, which can cause the skill to activate for unrelated user requests. This creates prompt-routing risk: the agent may invoke the skill outside its intended scope, producing irrelevant guidance or interfering with safer, more appropriate skills.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The invocation guidance mixes broad keywords such as common everyday terms with weak scope boundaries, increasing the chance of accidental or excessive activation. In an agent environment, ambiguous routing can misapply the skill to unrelated conversations, reducing reliability and potentially causing unsafe task handling if a more specialized skill should have been chosen.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.