Back to skill

Security audit

Work Productivity Proactive Agent Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-style workflow helper with broad activation wording but no code, persistence, credential use, or data-moving behavior.

Install only if you want a broadly routed workflow-planning helper. Review or narrow its trigger terms if your environment relies on precise skill routing, since it may activate for generic productivity or bug-fix requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and semantically overlap with many ordinary productivity requests, which can cause the skill to activate in contexts the user did not intend. In an agent ecosystem, overbroad routing can lead to incorrect tool or workflow selection, unwanted instruction injection into unrelated tasks, and reduced trustworthiness of downstream outputs.

Vague Triggers

High
Confidence
90% confidence
Finding
The trigger phrases are broad, generic, and overlap with common user language such as 'task', 'needs', and 'bug fix', which can cause the skill to activate outside its intended scope. In an agent workflow context, over-triggering can misroute user requests, invoke unintended behavior, and increase the chance that unrelated conversations are transformed by this skill without clear user intent.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very generic terms such as "task," "needs," "partners," and "proactive," which can match ordinary user requests unrelated to this skill. Overly broad activation increases the chance of unintended skill invocation, causing prompt-routing confusion and accidental application of this skill's instructions in inappropriate contexts.

Vague Triggers

High
Confidence
92% confidence
Finding
The description says to use the skill when a user asks for broad concepts like "work-productivity," "proactive," "task," or any practical workflow or analysis support, without clear boundaries for activation. This ambiguity can cause the orchestrator or user to apply the skill far outside its intended scope, leading to misrouting, instruction collisions, and unsafe overreach into unrelated tasks.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list includes very broad everyday terms such as "task", "needs", and "partners", which can cause the skill to activate in many unrelated conversations. Overbroad activation increases the chance that the agent invokes this skill out of context, leading to confused behavior, prompt-scope bleed, or accidental application of workflow guidance where it was not intended.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manifest description is very broad and says to use the skill whenever users ask for work-productivity, proactive, transform, task, or practical support, without strong boundaries on what is in or out of scope. This ambiguity can cause unintended routing and overuse of the skill, especially because the described domain overlaps with many ordinary assistant requests.

Vague Triggers

High
Confidence
93% confidence
Finding
The manifest description and default prompt are overly broad, using generic terms like 'work-productivity', 'proactive', 'transform', 'task', and 'practical workflow' without meaningful trigger constraints. This can cause unintended or implicit invocation for unrelated user requests, expanding the skill's activation surface and increasing the chance that sensitive context is routed into the skill unexpectedly.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences are broad, natural-language phrases that could match many ordinary user requests unrelated to this specific skill. That can cause accidental invocation of the skill in contexts where it is not appropriate, leading to workflow confusion, incorrect task routing, or unintended application of the skill's guidance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.