Back to skill

Security audit

Work Productivity Proactive Agent Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but no evidence of unsafe actions or data access.

Before installing, consider whether you want this skill to auto-activate broadly. It appears safe as a guidance-only helper, but its triggers should ideally be narrowed or used by explicit invocation to avoid unrelated requests being routed into this workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger phrases are extremely generic and overlap with normal user requests such as asking for help, workflows, tasks, or bug fixes. In an agent-routing context, this can cause the skill to activate unintentionally, leading to prompt hijacking of unrelated conversations, incorrect tool selection, or leakage of control to a skill the user did not explicitly request.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match ordinary, non-specific user requests such as asking for help with tasks, workflows, or bug fixes. In an agent-routing environment, this can cause the skill to activate unexpectedly, increasing the chance of misrouting user intent and exposing users to actions or outputs they did not explicitly request.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list includes very generic terms like 'task', 'needs', 'partners', and 'proactive', which are common in ordinary user requests and can cause the skill to activate outside its intended scope. In an agent environment, this creates an over-broad routing surface that may lead to inappropriate invocation, user confusion, or unintended application of workflow guidance in unrelated contexts.

Vague Triggers

High
Confidence
91% confidence
Finding
The manifest description says to use the skill when a user asks for broad concepts like 'work-productivity', 'proactive', 'transform', or 'task', which are ambiguous and overlap with many benign requests. This can cause accidental selection of the skill in unrelated conversations, increasing the chance of misrouting and reducing the reliability and safety of skill orchestration.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger list includes very broad everyday terms such as "task", "needs", and similar generic workflow words, which can cause the skill to activate in many unrelated conversations. In an agent environment, over-broad activation can redirect user requests into unintended workflows, create confusing behavior, and increase the chance that the skill is invoked on sensitive or irrelevant tasks.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description defines activation conditions with a wide set of loosely bounded categories like work-productivity, proactive, transform, and task, without specifying exclusions or required context. This makes accidental invocation more likely and reduces predictability, which is dangerous in multi-skill systems because the wrong skill may capture requests and produce irrelevant or risky guidance.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt is broadly phrased and includes generic terms like 'help me' plus a long natural-language description, which can overlap with ordinary user requests. This increases the chance of unintended skill activation, causing the agent to inject workflow-specific guidance when the user did not explicitly request this skill.

Vague Triggers

High
Confidence
97% confidence
Finding
Implicit invocation is enabled without any visible trigger constraints, allowing the platform to auto-select this skill based on broad semantic similarity. In a skill focused on proactive workflows, this raises the risk of overreach, unintended execution paths, and user-confusing behavior where the agent applies the skill in contexts the user did not authorize.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences are broad, natural-language phrases that could match ordinary user requests unrelated to this specific skill, causing unintended activation. In an agent ecosystem, overbroad activation can route users into the wrong workflow, create confusing autonomy, and increase the chance that the skill acts on partial or mismatched context.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The usage signals and trigger guidance do not sufficiently bound the skill’s scope, mixing generic productivity terms like 'task' and 'needs' with broad workflow language. This makes accidental invocation more likely and can cause the agent to apply this skill in contexts where its assumptions, artifacts, or planning behavior are inappropriate.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.