Back to skill

Security audit

Work Productivity Proactive Agent Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with broad activation wording, but it does not install code, read private data, persist, or take privileged actions.

Before installing, be aware that this skill may be selected too often because its triggers are generic. It is otherwise low-risk: it provides workflow guidance and documentation-style outputs, with no installed code or privileged access in the artifact.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad, generic, and overlap with ordinary user requests such as asking for practical workflows, bug fixes, or task help. In an agent ecosystem, this can cause accidental invocation or over-selection of the skill, leading the agent to apply this workflow in contexts the user did not explicitly request, which can misroute tasks or expose unrelated user context to the skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad enough to match ordinary productivity requests such as asking for practical workflows, task help, or bug fixes. In an agent-routing context, this can cause unintended activation, making the skill intercept user requests it was not specifically selected for and potentially steering outputs based on its own embedded framing rather than the user's actual intent.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The file list states that this README is the Chinese user guide and pairs it with Chinese-language documentation, which can bias the experience toward a specific locale if surfaced automatically without checking user preference. While this is not a direct code-execution risk, it can degrade usability, cause misunderstanding of safety instructions, and increase the chance of user error if the wrong-language documentation is selected by default.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list is overly broad and includes generic words like 'task', 'transform', 'needs', and 'bug fix', which can cause this skill to activate for many unrelated everyday requests. In an agent environment, overbroad activation can unintentionally route user requests into this skill, increasing the chance of inappropriate behavior, confusion, or unsafe automation being applied outside its intended scope.

Vague Triggers

High
Confidence
93% confidence
Finding
The manifest description uses broad invocation language such as 'use when a user asks for work-productivity, proactive-agent, proactive, transform, task, or needs a practical workflow,' which is ambiguous and likely to match routine requests far beyond the skill's intended scope. Because descriptions are often used by routers or selection heuristics, this can lead to accidental invocation and unnecessary exposure of the skill's instructions in unrelated contexts.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes very broad everyday terms such as "task", "needs", and "partners", which can cause this skill to activate in many unrelated conversations. Over-broad activation increases the chance that the agent injects workflow guidance or takes over routing when the user did not intend to invoke this skill, creating prompt-selection and scope-confusion risk.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says to use the skill whenever the user mentions broad categories like work-productivity, proactive, transform, or task, but it does not clearly define boundaries or non-applicable cases. This ambiguity can lead to accidental invocation, misrouting, and inappropriate skill application, especially in systems that auto-select skills from natural-language metadata.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill enables implicit invocation while describing itself in very broad, generic terms such as helping with workflows, tasks, checklists, analysis, and implementation support. This creates an overbroad trigger surface where the platform may auto-invoke the skill for many unrelated prompts, increasing the chance of unintended prompt injection exposure, privilege misuse, or confusing the user about why the skill was activated.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences and keywords are broad enough to match many ordinary productivity requests, which can cause this skill to activate outside its intended scope. Overbroad activation increases the chance of unintended workflow injection, user confusion, and inappropriate handling of requests that should have been routed to a different skill or kept as general conversation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.