Back to skill

Security audit

Work Productivity Proactive Agent Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with broad activation wording but no hidden execution, credential access, persistence, or destructive behavior.

Installers should know this skill may be selected for broad productivity or task-planning prompts. It appears safe as a documentation workflow helper, but narrowing its trigger keywords would reduce accidental activation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger examples are broad, natural-language phrases such as 'Help me...' and 'I need a practical workflow...', which can overlap with ordinary user requests and cause unintended skill activation. In an agentic workflow skill, accidental invocation can redirect user intent, inject workflow behavior where it was not requested, and increase the chance of inappropriate autonomy or unexpected task execution.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad, generic, and overlap with common user language such as 'help me', 'practical workflow', 'task', and 'bug fix'. In an agent-routing context, this can cause unintended activation or invocation of the skill on unrelated requests, which may misroute user intent, override more appropriate skills, or expand the skill's operational scope beyond what the user expected.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger list includes very common words such as "task," "needs," and "partners," which can cause the skill to activate in many unrelated conversations. Overly broad activation increases the chance of unintended invocation, causing workflow hijacking, irrelevant guidance, or interference with a more appropriate skill.

Vague Triggers

High
Confidence
89% confidence
Finding
The manifest description uses broad intent language like "use when a user asks for work-productivity, proactive-agent, proactive, transform, task" and "needs a practical workflow," which is ambiguous enough to match a wide range of normal requests. This can make routing overly permissive and lead to the skill being selected outside its intended scope, reducing reliability and potentially overriding safer or more specialized skills.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes very broad everyday terms such as "task", "needs", and "partners", which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance that this skill injects irrelevant workflow instructions into contexts where they were not requested, creating prompt-routing confusion and potentially interfering with safer or more appropriate skills.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description says to use the skill when users ask for broad categories like work-productivity, proactive, transform, or task, without clearly defining boundaries. This ambiguity can make the skill eligible for too many requests, increasing misrouting risk and causing the agent to apply this skill outside its intended domain.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The manifest’s display and prompt text use broad, generic phrasing such as helping with 'work-productivity', 'proactive', 'task', 'workflow', and 'implementation support' without clear boundaries on when the skill should be invoked. Combined with implicit invocation, this increases the chance the agent is selected in contexts the user did not intend, which can cause prompt-scope expansion, unintended tool usage, or unsafe delegation to a loosely scoped skill.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences and keywords are broad enough to match many generic productivity or task-oriented requests, which can cause the skill to activate outside its intended scope. In an agent environment, overbroad routing can lead to inappropriate handling, user confusion, and accidental application of workflow logic to unrelated tasks, increasing the chance of unsafe or low-quality downstream actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.