Back to skill

Security audit

Work Productivity Proactive Agent Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

The skill is documentation-only and not destructive, but its very broad triggers plus implicit auto-invocation could make it affect unrelated user tasks.

Review this skill before installing if you rely on automatic skill selection. It does not appear to run code or access sensitive data by itself, but it should have narrower triggers or explicit invocation to avoid shaping unrelated productivity, bug-fix, or implementation requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger examples are broad, generic phrases like 'Help me' and 'I need a practical workflow' combined with common work-productivity terms, which can cause the skill to activate for many unrelated everyday requests. In an agent ecosystem, over-broad activation can route user prompts into this skill unexpectedly, leading to inappropriate workflow injection, confusion, or unintended handling of tasks the user did not explicitly delegate to this skill.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are extremely broad and include generic terms like 'task', 'transform', 'needs', and 'bug fix', which can cause the skill to activate on ordinary unrelated requests. In an agent ecosystem, this creates unintended invocation and prompt-scope capture risk, potentially overriding more appropriate skills or injecting workflow behavior where the user did not request it.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes very generic terms like "proactive," "transform," "task," "needs," and "bug fix," which are common in normal conversations and can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of unintended routing, context hijacking, or the skill influencing unrelated tasks where its guidance may be inappropriate or lower quality.

Vague Triggers

High
Confidence
94% confidence
Finding
The description uses broad, catch-all language such as "use when a user asks for work-productivity, proactive-agent, proactive, transform, task" and "needs a practical workflow, artifact, checklist, analysis, or implementation support," which lacks clear boundaries. This can make the skill eligible for a wide range of unrelated requests, creating misrouting risk and allowing the skill to inappropriately shape responses in contexts it was not designed for.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list includes very generic words such as "proactive," "task," "needs," and "bug fix," which are common in normal conversation and can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of accidental invocation, context hijacking, or the skill influencing unrelated workflows where its assumptions or automation patterns do not fit.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The description says to use the skill when a user asks for broad categories like work-productivity, proactive-agent, proactive, transform, or task, which makes activation conditions ambiguous and subjective. This can lead to unintended routing of user requests into this skill, reducing predictability and potentially exposing users to irrelevant automation or outputs that bypass more appropriate specialized skills.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt and description use very broad, generic trigger language such as 'work-productivity,' 'proactive,' 'task,' and 'practical workflow,' which does not clearly constrain when the skill should activate. This can cause the platform to invoke the skill in unrelated contexts, increasing the chance of prompt-surface expansion, user confusion, and unintended access to conversations where the skill is not actually needed.

Vague Triggers

Medium
Confidence
93% confidence
Finding
Enabling implicit invocation without any visible narrowing conditions allows the skill to be auto-selected based on broad matching rather than deliberate user choice. In combination with the vague description, this raises the risk of over-invocation, unexpected behavior, and accidental routing of sensitive or irrelevant tasks into this skill's prompt context.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentences and keywords include very broad, common terms such as "help me," "practical workflow," "transform," and "task," which can cause this skill to activate for many unrelated requests. Over-broad invocation increases the chance of accidental routing, causing the agent to apply the wrong workflow, potentially producing irrelevant actions or interfering with safer or more appropriate skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.