Back to skill

Security audit

Work Productivity Proactive Agent Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but it does not install code, persist, read secrets, or perform hidden actions.

Before installing, be aware that the skill may activate for generic productivity or bug-fix requests because its trigger wording is broad. It is otherwise low-risk from the inspected artifacts: there is no executable code, hidden install behavior, persistence, credential handling, or privileged data access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger phrases are broad, generic, and include common workflow terms like 'help me', 'practical workflow', 'transform', and 'task', which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad activation can route unrelated user requests into this skill, leading to unintended instruction application, confusion, or unsafe task handling if the skill is used when a more appropriate or safer workflow should have been selected.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests such as asking for practical workflows, tasks, bug fixes, or proactive help. This can cause unintended skill activation, leading the agent to apply this workflow in contexts the user did not explicitly request, which may create confusing behavior, prompt-routing errors, or execution of the wrong assistance path.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords are extremely broad terms like "proactive," "task," "needs," and "bug fix," which are likely to match many unrelated user requests. This can cause accidental invocation of the skill in contexts the user did not intend, increasing the chance of prompt-scope hijacking, irrelevant behavior, or unintended workflow substitution.

Vague Triggers

High
Confidence
95% confidence
Finding
The manifest description says to use the skill whenever a user asks for broad categories like work-productivity, proactive, transform, task, or implementation support, which creates an overly expansive activation surface. Because descriptions often influence routing and tool selection, this ambiguity can make the skill activate for many unrelated requests and interfere with safer or more appropriate skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrases are generic request templates such as "Help me" and "I need a practical workflow," which are common across benign conversations and many unrelated tasks. These examples reinforce weak routing signals and may train downstream invocation logic to over-trigger the skill on ordinary requests.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes generic terms like "proactive", "transform", "task", "needs", and "bug fix", which are common in ordinary user requests and can cause the skill to activate outside its intended scope. In an agent system, overly broad activation increases the chance of inappropriate routing, unexpected behavior, and accidental application of this skill to unrelated tasks.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The invocation description allows use for very broad categories such as work-productivity, proactive-agent, proactive, transform, and task, without clearly defining what requests are in scope versus out of scope. This ambiguity can make the orchestrator over-select the skill, leading to misrouting, confusing outputs, or suppression of more appropriate specialized skills.

Vague Triggers

High
Confidence
94% confidence
Finding
The default prompt and description are broad, keyword-heavy, and cover generic terms like "work-productivity," "proactive," "task," and "analysis," which can cause the skill to match many unrelated user requests. This increases the chance of unintended activation, causing the agent to introduce the wrong workflow, expose unintended capabilities, or interfere with user intent.

Vague Triggers

High
Confidence
97% confidence
Finding
Enabling implicit invocation without tight activation constraints allows the platform to auto-select this skill based on vague semantic similarity rather than deliberate user choice. In combination with the broad prompt/description, this can lead to frequent accidental invocation, creating prompt-scope confusion and increasing the risk that the agent performs actions or provides guidance outside the user's intended context.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is broad enough to match common user phrasing unrelated to this specific skill, which can cause the agent to invoke the skill in the wrong context. In a proactive workflow skill, over-triggering increases the chance of irrelevant automation, confusing outputs, and unintended handling of user tasks or artifacts.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger guidance is ambiguous and insufficiently scoped, so the routing logic may select this skill for loosely related requests. That can misdirect user interactions, reduce reliability, and create opportunities for prompt-routing mistakes where the skill operates on tasks it was not meant to handle.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The overall trigger guidance lacks specificity and does not include exclusion criteria, making accidental or overly broad activation more likely. In agent skill ecosystems, poor trigger precision is dangerous because it can cause inappropriate tool selection, unexpected automation behavior, and degraded trust in system outputs.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.