Back to skill

Security audit

Work Productivity Proactive Agent Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad auto-activation language, but I found no hidden code, data access, persistence, or destructive behavior.

Before installing, be aware that this skill may be invoked too easily because its triggers are generic and implicit invocation is enabled. It appears safe as a workflow helper, but users or maintainers should tighten activation language if they want predictable skill routing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are broad, generic, and overlap with normal user requests like asking for practical workflows, task help, or bug fixes. This can cause unintended skill invocation and prompt routing collisions, increasing the chance the skill activates in contexts the user did not explicitly intend, which is especially risky for a proactive workflow skill that may shape actions or outputs broadly.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are broad, generic, and include common terms like 'task', 'proactive', and 'needs', which increases the chance the skill will activate for unrelated user requests. In an agentic workflow context, unintended invocation can cause the wrong workflow to take over a conversation, leading to confusing actions, irrelevant outputs, or accidental processing under the wrong assumptions.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes very generic terms such as "proactive," "transform," "task," "needs," and "bug fix," which are common across many unrelated user requests. This can cause the skill to activate outside its intended scope, leading to inappropriate routing, user confusion, or unintended influence over conversations that should be handled by other skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The manifest description says to use the skill when a user asks for broad concepts like work-productivity, proactive, transform, task, or practical workflow support, but it does not clearly define exclusion criteria. This ambiguity increases the chance of accidental invocation and overbroad applicability, especially in ecosystems where skill selection is automated or heuristic-driven.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes very generic terms such as "task", "transform", "needs", and "bug fix", which can match many unrelated user requests and cause the skill to activate unexpectedly. Over-broad activation increases the chance that this skill influences conversations outside its intended scope, leading to incorrect workflow injection, user confusion, or accidental execution of unsuitable guidance.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation description says to use the skill when a user asks for broad categories like work-productivity, proactive, transform, task, or practical workflow support, which is vague enough to cover a large portion of normal assistant requests. This makes the routing boundary unclear and can cause unintended skill selection, reducing reliability and potentially surfacing advice that is mismatched to the user's real intent.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The manifest description and default prompt are broad, vague, and trigger on generic terms like 'work-productivity,' 'proactive,' 'task,' and requests for 'practical workflow' or 'analysis.' This can cause the skill to be selected in contexts far beyond its intended use, increasing the chance of unintended execution, prompt-context leakage, or unsafe action routing by an agent orchestrator.

Vague Triggers

High
Confidence
98% confidence
Finding
Enabling implicit invocation while the skill remains loosely scoped is dangerous because the agent platform may auto-activate it without clear user intent. In this context, the skill is framed as a broad helper for workflows, checklists, analysis, and implementation support, which makes accidental or excessive invocation more likely and expands the attack surface for misrouting and unintended behavior.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger sentences are broad, natural-language phrases that could match many ordinary user requests unrelated to this specific skill, causing accidental or excessive invocation. In an agent ecosystem, overbroad activation can route user tasks into the wrong workflow, leading to confusion, unintended actions, or inappropriate handling of sensitive requests under the banner of a 'proactive' helper.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.