Back to skill

Security audit

Work Productivity Proactive Agent Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable workflow helper with overly broad activation wording but no hidden, destructive, credential-seeking, or persistent behavior.

Installers should be aware that this skill may be selected for broad productivity or task-help requests because implicit invocation is enabled and the trigger words are generic. It is otherwise a documentation-style helper and does not add executable code or privileged access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad, generic, and partly malformed, making the skill likely to activate for loosely related requests such as general productivity, bug-fixing, or task help. In an agent ecosystem, overbroad activation can cause unintended routing, prompt interference, or execution of the wrong workflow, which is especially risky for proactive-agent behavior that may take multi-step actions based on limited user intent.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords and example invocations are extremely broad (e.g., 'task', 'transform', 'needs', 'bug fix'), which can cause the skill to activate for many unrelated user requests. In an agentic workflow, over-broad activation increases the chance of unintended routing, inappropriate workflow execution, and accidental disclosure or modification of work context when the user did not intend to use this skill.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list is excessively broad, including generic terms like "proactive," "transform," "task," and "needs" that commonly appear in unrelated requests. This can cause the skill to activate outside its intended scope, leading to inappropriate routing, response hijacking, or accidental application of workflow guidance where it does not belong.

Vague Triggers

High
Confidence
93% confidence
Finding
The description says to use the skill when a user "asks for work-productivity, proactive-agent, proactive, transform, task," or needs broad forms of support, which is ambiguous and expansive. Such loose invocation criteria increase the chance that ordinary user requests will inappropriately trigger this skill, potentially overshadowing more suitable skills or causing unintended behavior.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger sentences merely repeat vague requirement text and do not show boundaries, disambiguation, or examples of when the skill should not be used. This encourages overbroad matching and makes downstream invocation logic more error-prone, especially in environments that rely on examples to infer routing behavior.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes very broad everyday terms such as "task", "needs", and "partners", which can cause the skill to activate in many unrelated conversations. Over-broad activation is dangerous because it can unexpectedly steer user interactions, override more appropriate skills, or inject workflow behavior where the user did not intend it.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description says it should be used when users ask for broad categories like work-productivity, proactive, transform, or task, but it does not clearly define boundaries for when the skill should or should not engage. This ambiguity increases the chance of accidental invocation and scope creep, which can make the agent behave unpredictably or apply the wrong workflow to unrelated user requests.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The file is presented only as a Chinese-language regionalized skill without any indication that language should follow user preference or be switchable. While not a direct code-execution risk, this can cause misrouting, misunderstanding of instructions, or unintended behavior if the agent applies a language-specific skill to users who did not request that locale.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The default prompt is overly broad and uses common everyday phrasing, which increases the chance the skill will be invoked in situations the user did not explicitly intend. In a proactive workflow helper, unintended activation can steer unrelated conversations, inject unrequested guidance, or expand the skill's influence beyond an appropriate scope.

Vague Triggers

High
Confidence
96% confidence
Finding
Enabling implicit invocation without meaningful activation constraints allows the system to auto-select this skill based on loose semantic matches rather than clear user consent. Because this skill is framed around broad work-productivity and proactive assistance, misrouting could frequently occur and cause unrequested actions, recommendations, or workflow changes in unrelated contexts.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger phrases are extremely generic (for example, 'Help me', 'I need a practical workflow', and broad productivity/task terms) and can match many ordinary user requests that are unrelated to this specific skill. In an agent-routing context, this can cause unintended activation, over-collection of user context, or inappropriate delegation to this skill, reducing reliability and potentially exposing downstream workflows to prompt-routing abuse or confusion.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.