Back to skill

Security audit

Work Productivity Proactive Agent Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk workflow helper skill with overly broad activation wording but no executable code, persistence, credential use, or hidden data handling.

Before installing, consider whether you want this skill to activate implicitly; its trigger language is broad enough that it may appear during ordinary productivity or bug-fix requests. Prefer explicit invocation if your environment allows it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad, generic, and partially duplicated from the requirement text, making it easy for the skill to activate in contexts the user did not explicitly intend. In an agent ecosystem, overbroad activation can cause misrouting, unintended workflow execution, and confused delegation to this skill instead of a more appropriate or safer one.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords and example invocations are very broad terms such as "task," "transform," and "proactive," which can match many unrelated user requests and cause unintended skill activation. In an agent workflow context, accidental invocation can steer conversations, alter outputs, or apply workflow behaviors the user did not request, increasing the risk of misexecution and confusion.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list contains highly generic terms like "proactive," "task," "needs," and "bug fix," which are common in ordinary user requests and can cause unintended skill activation. Over-broad activation increases the chance that this skill intercepts unrelated conversations, leading to prompt-scope confusion, inappropriate workflow injection, or accidental precedence over more suitable skills.

Vague Triggers

High
Confidence
91% confidence
Finding
The manifest description uses broad invocation language such as "Use when a user asks for work-productivity, proactive-agent, proactive, transform, task," without clear boundaries or exclusivity rules. This ambiguity can cause the orchestration layer to select the skill for many unrelated requests, creating misrouting risk and making prompt injection or unwanted workflow steering easier to trigger.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger sentences model activation on everyday phrasing like "Help me" and "I need a practical workflow," which overlaps with normal user language. Even if intended as examples, such patterns can train or bias routing systems toward over-activation, increasing accidental invocation and reducing the reliability of skill selection.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes very generic terms such as "proactive", "task", "needs", and "bug fix", which are likely to appear in many unrelated conversations. This can cause the skill to activate outside its intended scope, leading to incorrect routing, prompt interference, or unintended use of workflow instructions in contexts where they do not apply.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The description says the skill should be used whenever a user asks for broad categories like work-productivity, proactive-agent, proactive, transform, or task, or generally needs practical workflow or implementation support. This scope is ambiguous and overbroad, which increases the chance of accidental invocation and misapplication of the skill in unrelated requests.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The default prompt uses broad, natural-language trigger terms such as 'help me' and generic productivity phrasing, which can cause the skill to be invoked in many routine conversations without clear user intent. Because implicit invocation is enabled, this increases the chance of accidental activation, unexpected instruction injection into unrelated workflows, and reduced user control over when the skill participates.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentences are broad, generic phrases such as 'Help me' and 'I need a practical workflow', which can cause the skill to activate in situations far beyond its intended scope. In an agent environment, this can lead to accidental invocation, context confusion, and inappropriate routing of user requests to this skill, reducing predictability and possibly interfering with safer or more relevant skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.