Back to skill

Security audit

Work Productivity Proactive Agent Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but no hidden execution, data access, persistence, or destructive behavior.

Install only if you want a general proactive-agent workflow planning helper. Be aware it may be invoked too broadly because of generic trigger words such as task, needs, transform, and proactive; explicit invocation by skill name is safer until the publisher narrows the triggers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger phrases are broad, generic, and partially malformed, which can cause the skill to activate for unrelated user requests. In an agent ecosystem, overbroad activation increases the chance that the skill intercepts tasks outside its intended scope, leading to incorrect workflow guidance, unintended prompt injection surface, or confusing delegation behavior.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad, generic, and include common terms like "task," "proactive," and "needs," which can cause the skill to activate in contexts the user did not intend. In an agent workflow setting, accidental activation can route unrelated user requests into this skill, producing incorrect workflow transformations, confusing outputs, or unintended handling of sensitive work content.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes highly generic terms such as "proactive," "transform," "task," "needs," and "bug fix," which can cause the skill to activate for many unrelated user requests. Over-broad activation increases the chance the agent routes conversations into this skill unexpectedly, creating prompt-scope confusion and making downstream behavior easier to influence indirectly.

Vague Triggers

High
Confidence
95% confidence
Finding
The manifest description says to use the skill when a user asks for broad concepts like work-productivity, proactive, transform, task, or practical support, which is ambiguous and likely to over-match normal conversation. In an agent ecosystem, such vague invocation criteria can lead to unintended skill selection, causing misrouting, context bleed, and an expanded attack surface for prompt injection through unrelated tasks.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes very broad everyday terms such as "task", "needs", and "partners", which can cause the skill to activate in many unrelated conversations. Overbroad activation increases the chance of accidental routing, causing the agent to apply this workflow in the wrong context and potentially override more appropriate or safer skills.

Vague Triggers

High
Confidence
92% confidence
Finding
The description says the skill should be used for broad categories like work-productivity, proactive, transform, and task, without clear boundaries. This ambiguity makes invocation policy hard to enforce consistently and can lead to unintended skill selection, especially in multi-skill environments.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The example trigger phrases are truncated, repetitive, and do not clearly show the limits of valid activation. Without contrasting negative examples, implementers may generalize too broadly and trigger the skill for loosely related requests.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt contains very broad, everyday trigger language such as 'help me' and generic work-assistance phrasing, which can cause the skill to be invoked in many unrelated contexts. In combination with a proactive workflow helper role, this increases the chance of unintended activation, context capture, and user confusion about which agent behavior is operating.

Vague Triggers

Medium
Confidence
94% confidence
Finding
Enabling implicit invocation without clear trigger constraints allows the skill to activate based on loosely related user requests, which can lead to overreach and accidental routing. Because this skill is framed broadly around productivity, workflows, fixes, and implementation support, the lack of guardrails makes unintended invocation more likely and amplifies the effect of the broad default prompt.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrase begins with a very broad everyday request pattern ('Help me ...'), which can cause the skill to activate in contexts far outside its intended scope. In an agent ecosystem, overly generic activation logic can route unrelated user requests into this skill, creating prompt/skill hijacking opportunities, wrong-tool invocation, and unsafe automation based on mismatched context.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation sentence is ambiguous and too unspecific about when the skill should run, so unrelated requests may satisfy the trigger heuristics. Because this skill is designed to produce workflows and implementation support, accidental activation could cause it to generate authoritative-looking but irrelevant or unsafe actions for the wrong task.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.