Back to skill

Security audit

Work Productivity Proactive Agent Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with no executable code, credentials, persistence, or data access, though its automatic activation wording is broader than necessary.

This skill appears safe to install as a workflow helper, but users should be aware it may activate more often than intended because its trigger terms are broad. Prefer explicit invocation when using it, and consider narrowing the trigger wording if maintaining the skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentences and keywords are broad enough to cause the skill to activate for generic productivity or task-related requests that may not actually need this workflow. Over-broad activation can route unrelated user prompts into the skill unexpectedly, increasing the chance of incorrect behavior, unintended instruction precedence, or accidental use in contexts the author did not scope or test.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases and keywords are broad, generic, and aligned with common workplace requests such as 'task', 'help me', 'practical workflow', and 'bug fix'. In an agent-routing system, this can cause the skill to activate unexpectedly for unrelated conversations, leading to prompt/context hijacking at the orchestration layer, incorrect tool selection, or unintended influence over user workflows.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very generic terms like "proactive," "transform," "task," "needs," and "bug fix," which are common in ordinary user requests and can cause the skill to activate unintentionally. Over-broad activation increases the chance that the skill is invoked outside its intended context, leading to confused routing, inappropriate guidance, and potential interference with more relevant skills or safety controls.

Vague Triggers

High
Confidence
93% confidence
Finding
The manifest description uses broad phrases like "Use when a user asks for work-productivity, proactive-agent, proactive, transform, task" and "needs a practical workflow," which can match a wide range of unrelated requests. This ambiguous activation guidance can cause unintended invocation, expanding the skill's operational scope beyond what the user intended and making agent behavior less predictable.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes very broad everyday terms such as "task", "needs", and "partners", which can match many unrelated user requests and cause the skill to activate outside its intended scope. In a proactive-agent workflow skill, accidental invocation can steer conversations, inject irrelevant workflow guidance, or override more appropriate skills, reducing reliability and increasing the chance of unsafe or confusing automation behavior.

Vague Triggers

High
Confidence
91% confidence
Finding
The skill description says it should be used when users ask for broad categories like work-productivity, proactive, transform, or task, which creates unclear activation boundaries. This ambiguity makes the skill eligible for many unrelated contexts, increasing the risk of over-triggering and causing the agent to apply this workflow helper where it does not fit.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt includes a very broad invocation phrase tied to generic terms like work productivity and proactive help, which can overlap with ordinary user requests. This increases the chance of accidental activation, causing the skill to inject its workflow behavior into unrelated conversations and potentially influence agent actions without clear user intent.

Vague Triggers

High
Confidence
97% confidence
Finding
Implicit invocation is enabled with no visible constraints or tight trigger conditions, allowing the skill to activate automatically based on ambiguous user language. In an agent workflow helper, this can silently alter task execution, recommendations, or generated artifacts in contexts where the user did not intend to use this skill.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger phrases are broad, generic, and include common terms like "help me," "practical workflow," "task," and "needs," which can cause this skill to activate for many unrelated requests. In an agent-routing context, overbroad matching can misroute user prompts, override more appropriate skills, and increase the chance that users receive irrelevant or unintended workflow guidance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.