Back to skill

Security audit

Work Productivity Proactive Agent Workflow Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording but no hidden code, credential use, persistence, or destructive behavior.

Install only if you want a broad workflow-planning helper for proactive-agent style productivity work. Because implicit invocation is enabled with generic keywords, users should be aware it may activate on loosely related productivity or bug-fix requests unless the platform lets them require explicit invocation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger phrases are broad, generic, and overlap with common productivity or workflow requests, which can cause the skill to activate in situations the user did not explicitly intend. In an agent ecosystem, overbroad activation increases the chance of context hijacking, inappropriate routing, or accidental invocation of a workflow that influences outputs beyond the user's actual request.

Vague Triggers

High
Confidence
95% confidence
Finding
The description says to use the skill when a user asks for broad categories like "work-productivity," "proactive," "transform," or "task," without defining clear boundaries. Ambiguous invocation criteria increase the chance of accidental routing, making the skill behave like a catch-all and potentially interfering with safer or more relevant skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keywords include very common terms such as "proactive," "transform," "task," "needs," and "bug fix," which can match many unrelated user requests. This creates a prompt-scope vulnerability where the skill may activate unintentionally, causing irrelevant instructions to influence conversations or override more appropriate skills.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill enables implicit invocation while advertising a very broad, ambiguous purpose using generic trigger terms like work-productivity, proactive-agent, transform, task, checklist, analysis, and implementation support. This can cause the agent to auto-select the skill in many unrelated contexts, creating an overreach path where the skill influences workflows or outputs without sufficiently specific user intent.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger examples are broad enough to match routine user requests like 'help me' or 'I need a practical workflow,' which can cause the skill to activate outside its intended niche. In an agent ecosystem, overbroad activation can route unrelated tasks into this skill, producing irrelevant guidance, bypassing safer or more specific skills, and increasing the chance of unintended prompt capture or workflow interference.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad enough to match ordinary productivity requests such as asking for help, workflows, tasks, or bug fixes. In an agent ecosystem, this can cause unintended auto-invocation or over-selection of the skill, which may steer unrelated user requests into this workflow and create confused-deputy behavior or unexpected execution paths.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
Although the file is presented as a Chinese README, major user-facing sections including the title, demand description, capability description, keywords, and trigger phrases are written in English. This can effectively force a language choice on users without opt-in or an explicit documented justification.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger section provides broad keywords and example phrases but no negative examples or disambiguation rules. Without specificity, normal conversation can accidentally satisfy the trigger logic, leading to over-activation and expanding the skill's influence beyond its intended context.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The usage description defines activation conditions with a very wide scope, including generic categories like work-productivity, proactive, transform, and task, plus any request for workflows, artifacts, checklists, analysis, or implementation support. This ambiguity makes routing decisions unreliable and can lead to accidental invocation on common requests, broadening the skill’s effective authority beyond what users likely intended.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list includes very broad everyday terms such as "task", "needs", and "bug fix", which can match many unrelated user requests and cause the skill to activate outside its intended scope. Over-broad activation increases the chance that this skill overrides more appropriate skills or injects workflow guidance into conversations where it was not requested, reducing predictability and potentially influencing downstream actions.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation guidance defines positive signals but does not define boundaries, disallowed contexts, or fallback behavior when the match is ambiguous. That makes skill selection permissive and unpredictable, which can lead to accidental invocation on common productivity requests and reduce trust in routing accuracy.

Natural-Language Policy Violations

Low
Confidence
79% confidence
Finding
The file listing explicitly separates English and Chinese instruction and guide files, but this README does not state how the user's preferred language is selected or that language choice is optional. That can imply a fixed locale behavior without documented user opt-in.

Static analysis

No suspicious patterns detected.