Back to skill

Security audit

Work Productivity Pollyreach Gives Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad automatic invocation terms, but it does not request credentials, persistence, code execution, or destructive authority.

Before installing, expect this skill to be a general workflow/checklist helper. Consider narrowing or disabling implicit invocation if you do not want it to activate on ordinary productivity, phone, number, or workflow-related requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are broad, generic, and include fragments that could match ordinary user requests rather than a clearly scoped skill invocation. This increases the chance of unintended activation, causing the agent to apply this workflow in unrelated contexts and potentially override more appropriate skills or produce irrelevant actions.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The invocation guidance does not define clear scope, exclusions, or activation constraints, and the listed keywords include very common terms like 'every', 'phone', and 'done'. In an agentic environment, this ambiguity can cause excessive or incorrect routing, leading to workflow hijacking, noisy behavior, and reduced trust in automation.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keywords and example phrases are so generic that they can match ordinary user requests unrelated to this skill, causing unintended activation. In an agent ecosystem, over-broad invocation can route benign conversations into the wrong workflow, leading to confusing behavior, prompt hijacking surface expansion, or accidental handling of tasks the skill was not meant to control.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keyword list is excessively broad and includes common words like "every," "phone," "number," "ability," and "things," which can cause the skill to activate for many unrelated user requests. In an agent environment, this increases the chance of accidental routing, prompt-context contamination, and unintended execution of workflows that were not relevant to the user's intent.

Vague Triggers

High
Confidence
93% confidence
Finding
The invocation description says to use the skill when a user asks for broad terms like "work-productivity," "gives," "every," or "phone," making activation criteria ambiguous and overly inclusive. This can cause the system to select the skill in unrelated contexts, leading to misfires, irrelevant guidance, and possible interference with more appropriate skills or security boundaries.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger sentences are phrased so broadly that they reinforce unsafe matching behavior rather than clarifying scope. If examples are used by tooling or maintainers as guidance for routing, they can normalize activation on vague, everyday language and increase false-positive invocation rates.

Vague Triggers

High
Confidence
96% confidence
Finding
触发关键词包含 `every`、`phone`、`number`、`ability`、`things`、`done` 等高频日常词汇,会显著提高误触发概率,使该技能在与真实意图无关的普通对话中被调用。误触发会导致错误的工作流介入、响应偏离用户需求,并可能覆盖本应由更合适技能处理的任务。

Vague Triggers

Medium
Confidence
89% confidence
Finding
技能描述将适用范围定义为非常宽泛的“实用流程、产物、检查清单、分析或实现支持”,且围绕多个泛化关键词展开,缺少清晰边界和明确激活前提。这会让路由器或调用方难以区分该技能与其他通用 productivity/implementation 类技能的适用范围,增加错误选择和提示劫持式抢占的风险。

Vague Triggers

Medium
Confidence
91% confidence
Finding
示例触发句使用 `Help me`、`I need a practical workflow` 这类高度通用的表达,且仅附带被截断的需求描述,容易与大量普通用户请求重叠。示例通常会被作者和路由系统视为触发参考,因此这种写法会进一步放大误匹配和不精确激活问题。

Vague Triggers

Medium
Confidence
96% confidence
Finding
The skill enables allow_implicit_invocation without any visible activation constraints, which means it may be invoked during ordinary user requests without clear user intent. In a broadly scoped productivity helper, this increases the chance of unintended routing, prompt injection exposure, or confusing the user about which agent behavior is active.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt uses very broad, everyday language such as help me, practical help, workflow, checklist, analysis, and implementation support, which can overlap with many normal requests unrelated to this skill. Combined with implicit invocation, this makes accidental activation more likely and can cause the skill to capture conversations it was not specifically intended to handle.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrase includes extremely common words such as 'every', 'phone', 'number', and 'things done', which can cause the skill to activate for unrelated conversations. In an agent environment, over-broad activation can route arbitrary user requests into this skill, creating prompt-injection surface area, incorrect task handling, and unintended workflow execution.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger examples are vague and truncated, and they do not clearly define boundaries for when the skill should or should not run. That ambiguity increases accidental invocation risk and misrouting, especially because the skill is framed broadly around 'practical workflow' and 'implementation support' rather than a tightly scoped task.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.