Back to skill

Security audit

Work Productivity Self Improving Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording but no hidden execution, data access, persistence, or destructive behavior.

Before installing, be aware that this skill may be invoked more often than intended because its trigger terms are broad. It is otherwise low-risk: review generated workflows or code suggestions before applying them, as you would with any productivity assistant output.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentences are broad, repetitive, and closely mirror generic user intents, which increases the chance that the skill activates in contexts where it was not explicitly requested. In an agentic workflow, overbroad activation can cause unintended delegation, prompt routing mistakes, or application of self-improving/proactive behaviors to sensitive tasks without clear user consent.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad and map to common words like 'self', 'improving', and 'proactive', which can cause the skill to activate for many ordinary requests unrelated to the intended workflow. In an agent ecosystem, this can lead to unintended invocation, prompt/context hijacking of user tasks, and reduced predictability of which skill handles a request.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes extremely broad terms such as "self," "improving," and "proactive," which are common in ordinary user requests and can cause the skill to activate unintentionally. This increases the chance of prompt-routing errors, where a generic conversation is redirected into this skill’s workflow without clear user intent, potentially overriding better-matched skills or causing confusing autonomous behavior.

Vague Triggers

High
Confidence
93% confidence
Finding
The skill description says to use the skill when a user asks for broad concepts like work-productivity, self, improving, or proactive, without defining decision boundaries or disambiguation rules. In a skill-routing system, such vague activation criteria can make this skill match a large volume of unrelated requests, producing misfires and reducing predictability of agent behavior.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger phrases are highly generic and effectively teach the router or author to invoke the skill from vague wording like "They need practical help," which does not uniquely identify this capability. This reinforces ambiguous activation patterns and makes accidental or excessive routing more likely, especially in ecosystems with many overlapping skills.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger keywords are overly broad, including common terms like 'self', 'improving', and 'proactive' that can appear in many unrelated user requests. This can cause accidental activation of the skill outside its intended scope, leading to incorrect routing, irrelevant guidance, or interference with more appropriate skills.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The scope description is vague and does not clearly define activation boundaries or when the skill should not be used. Ambiguous activation rules increase the chance that the agent invokes this skill in unrelated contexts, which can degrade reliability and potentially override safer or more relevant workflows.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt contains very broad, everyday activation language such as helping with 'work-productivity' and 'practical help,' which can cause the skill to be invoked in situations far outside its intended scope. Because implicit invocation is enabled, this increases the chance of unintended routing, prompt confusion, and the skill influencing unrelated user requests without clear user intent.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests containing generic terms like 'help me', 'practical workflow', 'self', or 'improving', which can cause this skill to activate outside its intended scope. Overbroad activation is dangerous because it can hijack unrelated tasks, apply the wrong workflow, and increase the chance that agent behavior is steered by irrelevant or adversarially crafted prompts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.