Back to skill

Security audit

Work Productivity Proactive Agent Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-only workflow helper, but its broad auto-invocation wording may make it activate for unrelated productivity requests.

Installers should expect a low-risk workflow helper, but should narrow the trigger wording or disable implicit invocation if they want to avoid the skill being selected for ordinary task or productivity requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad and generic enough that the skill may activate for many unrelated requests containing common workflow terms like 'help me', 'practical workflow', 'task', or 'bug fix'. In an agentic environment, unintended invocation can cause the wrong workflow to steer user interactions, producing confused execution, prompt hijacking opportunities across skills, or actions taken under incorrect assumptions.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger phrases are broad enough to match common user requests such as asking for practical workflows, tasks, fixes, or implementation help, which can cause the skill to activate outside its intended scope. In an agent ecosystem, over-broad invocation increases the chance of unintended routing, confusing behavior, and accidental application of this workflow to unrelated or sensitive tasks.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very generic terms such as 'task', 'needs', and 'proactive', which can cause the skill to activate for many unrelated user requests. Over-broad activation increases the chance the agent routes sensitive or irrelevant prompts into this skill, creating scope confusion and unreliable behavior rather than precise invocation.

Vague Triggers

High
Confidence
94% confidence
Finding
The description says to use the skill when a user asks for broad concepts like 'work-productivity', 'transform', 'task', or practical support, which is effectively a catch-all routing rule. Ambiguous invocation boundaries can cause unintended selection of this skill over more appropriate ones, increasing misexecution risk and weakening safety guarantees based on least-privilege behavior.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger sentences are truncated and malformed, so they do not provide reliable guidance for when the skill should be invoked. Poor trigger examples can lead to accidental or inconsistent activation, especially when combined with already broad keyword rules.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes very broad everyday terms such as "task", "needs", and "partners", which can cause the skill to activate in many unrelated conversations. Overbroad activation increases the chance that the agent applies the wrong workflow, injects irrelevant instructions, or crowds out more appropriate skills, reducing reliability and potentially causing unsafe task handling in adjacent contexts.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description says it should be used whenever a user asks for broad categories like work-productivity, proactive, transform, or practical workflow/checklist support, without clear boundaries. This ambiguous scope can lead to unintended invocation across a large range of requests, creating routing errors and increasing the risk of inappropriate guidance being applied outside the intended job-to-be-done.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
This file is authored entirely as a Chinese-language variant and does not indicate any user language negotiation or opt-in behavior. In multilingual environments, forced language presentation can confuse users, cause misunderstanding of workflow steps or safety guidance, and degrade correct execution of the skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt uses very broad, generic trigger language such as 'help me' and references common workflow terms, which can cause the platform to select this skill for loosely related requests. That increases the chance of unintended invocation, causing the agent to apply the wrong workflow, expose irrelevant capabilities, or interfere with user intent.

Vague Triggers

High
Confidence
96% confidence
Finding
Enabling implicit invocation without clear activation constraints allows the system to auto-trigger this skill based on weak semantic matches. In a broadly described productivity skill, this raises the risk of accidental activation across many unrelated requests, which can lead to misrouting, overreach in agent behavior, or unsafe execution of workflow guidance outside the intended context.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences and keywords are broad enough to match many ordinary productivity or task-oriented requests, which can cause the skill to activate outside its intended scope. In an agent-routing context, this creates prompt/skill hijacking risk, misroutes user requests, and may suppress more appropriate or safer skills by over-claiming common language.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.