Back to skill

Security audit

Work Productivity Proactive Agent Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper, but its automatic activation rules are too broad and may make it appear in unrelated tasks.

Before installing, be aware that this skill may be selected for generic productivity or task requests because its triggers are broad and implicit invocation is enabled. It appears safe as a workflow helper, but tighter activation wording would make it less intrusive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentences and keywords are broad enough to match many ordinary productivity requests, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad activation can route unrelated user tasks into this skill, leading to unintended instruction precedence, workflow confusion, and increased exposure to whatever behaviors the underlying skill implements.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad, generic, and partially duplicated from the demand statement, which can cause the skill to activate in contexts far beyond the author's intended scope. In an agent ecosystem, overbroad activation increases the chance of unintended invocation, workflow hijacking, or user confusion that could route unrelated requests into this skill and produce unsafe or misleading automation behavior.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list includes very common words such as "proactive," "transform," "task," "needs," and "partners," which can cause the skill to activate for many unrelated requests. Overbroad activation increases the chance the agent applies the wrong workflow, injects irrelevant instructions into normal conversations, or steals routing priority from more appropriate skills.

Vague Triggers

High
Confidence
91% confidence
Finding
The description says to use the skill when a user asks for broad concepts like "work-productivity," "proactive," "transform," or "task," plus any request needing a practical workflow or checklist. This ambiguous guidance can make the orchestrator select the skill for a wide range of unrelated prompts, expanding its influence beyond its intended scope and reducing safe, predictable routing.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keyword list includes very broad everyday terms such as "task", "needs", and "bug fix", which can match many unrelated user requests and cause the skill to be invoked unexpectedly. In an agent environment, overbroad auto-invocation can steer conversations into this workflow when the user did not intend it, increasing the chance of irrelevant guidance, prompt-scope interference, or accidental execution of the wrong process.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description says it should be used for broad categories like work-productivity, proactive, transform, and task, without defining meaningful boundaries. This weak scoping makes routing ambiguous and can cause the system to select the skill for loosely related requests, which is risky because the skill may shape outputs or workflows outside its intended domain.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The sample trigger phrases are themselves broad and formulaic, reinforcing permissive matching behavior rather than demonstrating constrained activation. If examples are used by routing heuristics, embeddings, or future maintainers as guidance, they can further increase false activations and widen the skill’s effective scope.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill metadata uses very broad activation and purpose language such as 'work-productivity,' 'proactive,' 'transform,' 'task,' and generic workflow support, while the default prompt is similarly vague and expansive. This can cause the agent to invoke the skill in contexts beyond its intended scope, increasing the chance of prompt-surface abuse, incorrect delegation, or unreviewed behavior being applied to unrelated user requests.

Vague Triggers

High
Confidence
95% confidence
Finding
Enabling implicit invocation without tight activation constraints allows the system to auto-select this skill based on loose semantic matches rather than deliberate user choice. In combination with the skill's broad description, this makes accidental or adversarial triggering more likely, which can lead to unauthorized workflow influence, misapplied instructions, or unsafe handling of unrelated tasks.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger sentence is broad and resembles normal user phrasing, which can cause the skill to activate unintentionally for unrelated requests. In an agent environment, overbroad invocation can route user inputs into the wrong workflow, causing confusing behavior, unwanted automation, or inappropriate handling of tasks the user did not intend this skill to perform.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation guidance is not clearly bounded, mixing broad keywords like "task" and "transform" with generic help-oriented phrasing. This increases the chance of accidental activation or skill shadowing, where this skill intercepts requests better handled by other skills, reducing reliability and potentially exposing user data or actions to an unintended workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.