Back to skill

Security audit

Work Productivity Proactive Agent Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation language, but no hidden code, credential access, persistence, or destructive behavior.

Install only if you want a general proactive-workflow planning helper. Be aware it may activate too often because its trigger terms are broad; review generated plans before acting on them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentences are extremely broad and include generic terms like 'help me', 'practical workflow', 'task', and 'needs', which can cause the skill to activate in contexts the user did not clearly intend. In an agentic system, overbroad activation increases the chance of unintended workflow execution, context hijacking, or inappropriate application of the skill to unrelated requests.

Vague Triggers

High
Confidence
96% confidence
Finding
The documented trigger keywords and example invocation phrases are extremely broad, including generic terms such as "task," "transform," and "needs," which can cause the skill to activate for many unrelated everyday requests. In an agent ecosystem, overbroad routing can silently divert user intent into the wrong workflow, causing unintended actions, confusing outputs, or unsafe automation when the skill is selected outside its intended scope.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The README mixes Chinese headings and body text with substantial English product names and requirement text, but does not explicitly state locale expectations or provide a language-selection mechanism. This can lead to user misunderstanding of scope, triggers, and safety guidance, which is especially risky for an agent skill because misinterpretation of routing or usage instructions can cause incorrect invocation or misuse.

Vague Triggers

High
Confidence
98% confidence
Finding
The skill description includes broad activation language such as 'use when a user asks for work-productivity, proactive-agent, proactive, transform, task' and generic requests for workflows, artifacts, checklists, or analysis. These terms are common across many unrelated conversations, so the skill may activate outside its intended scope and inject irrelevant or unsafe guidance into sessions that did not explicitly request it.

Vague Triggers

High
Confidence
99% confidence
Finding
The keyword list contains highly ambiguous everyday terms like 'task', 'needs', 'followers', and 'partners' without any scope constraints. Because trigger systems often rely on simple matching, these words can cause pervasive over-triggering, leading the skill to intervene in unrelated contexts and potentially override more appropriate instructions or workflows.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keyword list includes very broad everyday terms such as "task", "needs", and similar generic language, which can cause the skill to activate in many unrelated conversations. Overbroad activation increases the chance that the agent applies this workflow in the wrong context, leading to unintended instructions, confusion, or interference with more appropriate skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says the skill should be used when users ask for broad categories like work-productivity, proactive, transform, or task, but it does not clearly define boundaries or exclusion criteria. This ambiguity can cause accidental invocation and unreliable routing, especially in systems that use descriptions for automatic skill selection.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases are close to ordinary user requests and do not show counterexamples that should not activate the skill. In auto-routing environments, examples strongly influence matching behavior, so vague positive-only examples can broaden invocation beyond the intended scope.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt uses very broad activation language such as general help and workflow support, which can cause the skill to be invoked for ordinary user requests that were not meant to trigger it. In an agent setting, over-broad routing increases the chance of unintended prompt injection exposure, confusing behavior, or the skill influencing tasks outside its intended scope.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without meaningful activation constraints allows the platform to call this skill automatically based on loose semantic matches rather than clear user intent. That expands the skill’s effective attack surface and can lead to accidental invocation in unrelated contexts, where the skill may steer outputs or process adversarial content unexpectedly.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger examples and keywords are broad enough to match ordinary requests such as 'help me', 'task', 'workflow', or 'practical help', which can cause the skill to activate outside its intended scope. In an agent-routing context, this can lead to over-selection, prompt hijacking of unrelated tasks, reduced user intent fidelity, and accidental exposure of users to an overly powerful or mismatched workflow.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.