Back to skill

Security audit

Work Productivity Proactive Agent Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with overbroad activation wording, but it does not request sensitive access, persistence, command execution, or hidden data handling.

Install only if you want a broadly available productivity workflow helper. The publisher should narrow the trigger wording or disable implicit invocation to reduce accidental activation, but the reviewed artifacts do not show credential access, persistence, exfiltration, destructive behavior, or hidden execution.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are extremely broad and partially malformed, matching generic terms like 'proactive', 'task', and 'needs' that could cause the skill to activate in many unrelated contexts. In an agent environment, this can lead to unintended invocation, context hijacking, or the skill influencing workflows when the user did not intend to use it, reducing reliability and potentially exposing downstream actions to the wrong prompt logic.

Vague Triggers

High
Confidence
95% confidence
Finding
The documented trigger keywords and example invocations are extremely broad terms such as 'task', 'transform', 'needs', and 'bug fix', which can match many unrelated user requests. In an agent routing system, this can cause unintended activation and prompt interception, leading the skill to influence workflows it was not explicitly selected for.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description contains very broad activation terms and a wide usage scope, which can cause the skill to match many unrelated user requests. In an agent system, unintended activation can route user inputs into the wrong workflow, causing irrelevant actions, confusing outputs, or unsafe automation in contexts the skill was not designed for.

Vague Triggers

High
Confidence
99% confidence
Finding
The trigger list includes generic terms such as 'task', 'needs', and 'proactive', which are common in everyday requests and are not scoped to this skill's domain. This materially increases accidental invocation risk, and in a proactive-agent context that can lead to over-broad interception of user requests, misrouting, and inappropriate execution of workflow guidance where another skill or no skill should be used.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list is overly broad and includes common terms such as "task", "proactive", "needs", and "bug fix", which can overlap with many ordinary user requests. This can cause the skill to activate outside its intended scope, leading to incorrect routing, unexpected behavior, or overshadowing of more appropriate skills in a multi-skill environment.

Vague Triggers

High
Confidence
91% confidence
Finding
The skill description says it should be used when a user asks for broad categories like work-productivity, proactive-agent, proactive, transform, or task, or when they need practical workflow or implementation support. This boundary is vague enough that many unrelated requests could match, increasing the chance of accidental invocation and misapplication of the skill’s guidance.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt is highly generic and includes broad productivity-oriented phrasing such as helping with workflows, tasks, checklists, analysis, and implementation support. In combination with agent ecosystems that may auto-match on semantic relevance, this can cause the skill to be invoked in situations the user did not specifically intend, expanding the skill's authority and increasing the chance of prompt-scope confusion or unsafe task execution.

Vague Triggers

High
Confidence
97% confidence
Finding
Enabling implicit invocation without strict trigger constraints allows the platform to auto-activate this skill based on loose semantic matches. Because the skill is framed around common workplace concepts like productivity, tasks, and practical help, it could be invoked across many ordinary conversations, leading to unintended behavior, over-broad assistance, or accidental execution in contexts where the user did not consent to using this skill.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences are so generic that they can match ordinary user requests unrelated to this skill's intended scope, causing the agent to invoke the skill in inappropriate contexts. Over-broad activation increases the chance of prompt-routing mistakes, irrelevant workflow injection, and accidental override of more suitable skills or safer default behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.