Back to skill

Security audit

Work Productivity Proactive Agent Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a low-risk workflow helper, but its automatic activation wording is broader than it should be.

Installers should consider narrowing the trigger phrases or disabling implicit invocation if they want this skill to run only when explicitly requested. The reviewed artifact does not contain code execution, credential handling, persistence, or data exfiltration behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad and keyword-heavy, so the skill may activate for loosely related requests rather than clear, user-intended invocations. In an agent ecosystem, overbroad activation can cause unintended routing, prompt/context injection into unrelated tasks, or accidental execution of workflows the user did not explicitly request.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad and include generic terms like "help me," "I need a practical workflow," and common productivity-related keywords. This can cause the skill to activate for ordinary user requests unrelated to the intended scope, increasing the chance of unintended prompt injection surface, workflow hijacking, or incorrect skill invocation in mixed-agent environments.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description and usage guidance include broad, common terms like "work-productivity," "task," "transform," and "practical workflow," which are likely to match many unrelated user requests. This can cause unintended invocation of the skill, leading to context hijacking, user confusion, or the application of the wrong workflow in situations where a more appropriate skill should have been selected.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword trigger list contains vague and high-frequency terms such as "proactive," "task," "needs," "partners," and "bug fix" without qualifiers or exclusions. In a routing or auto-invocation system, these ambiguous triggers can cause the skill to activate for a large volume of unrelated prompts, increasing the chance of misrouting, inappropriate tool behavior, and interference with safer or more relevant skills.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list is overly broad, including generic terms like 'task', 'needs', 'partners', and 'bug fix' that commonly appear in unrelated conversations. This can cause accidental activation and context hijacking, where the skill intervenes outside its intended scope and influences workflows or outputs unexpectedly.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation description says to use the skill for broad categories such as work-productivity, proactive-agent, proactive, transform, and task, plus any need for practical workflows or artifacts. This ambiguity expands the skill's scope so widely that it may be selected for loosely related requests, increasing the chance of misapplication and unintended instruction influence.

Vague Triggers

High
Confidence
94% confidence
Finding
The default prompt and description are highly broad and keyword-heavy, covering generic terms like 'proactive,' 'task,' 'workflow,' 'analysis,' and 'implementation support.' This can cause the skill to activate for loosely related requests, increasing the chance of unintended routing, over-collection of user context, or inappropriate tool behavior in situations where the user did not explicitly request this skill.

Vague Triggers

High
Confidence
97% confidence
Finding
Enabling implicit invocation without tightly scoped triggers or guardrails allows the platform to invoke this skill automatically based on vague matches. In combination with the broad description, this materially raises the risk of accidental activation across unrelated conversations, which can lead to unexpected behavior, privacy concerns, or interference with user intent.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is broad and generic enough that normal user requests could accidentally activate this skill outside its intended scope. In an agent-routing system, this can cause mis-selection, leading the agent to follow an irrelevant workflow, produce inappropriate artifacts, or bypass more suitable skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation guidance does not clearly define boundaries for when the skill should and should not run, which increases the chance of unintended activation from common work-related phrasing. In a multi-skill environment, ambiguous routing can degrade reliability and safety by pulling in this skill for unrelated tasks and causing incorrect automation or advice.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.