Back to skill

Security audit

Work Productivity Self Improving Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with broad activation wording, but it does not install code, run commands, persist, or access sensitive data.

Before installing, be aware that this skill may activate on broad productivity or self-improvement language. It is best suited for explicit requests about self-improving or proactive agent workflows, reliability hardening, bug-fix process design, or adjacent skill design.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentence is broad enough that ordinary user requests containing generic phrases like 'help me' and 'practical workflow' could unintentionally activate this skill outside its intended scope. In an agent ecosystem, overbroad triggering can cause prompt hijacking at the routing layer, misapply the wrong workflow, or insert self-improving/proactive behaviors into unrelated tasks.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation examples define scope loosely and do not explain when the skill should not be used, making accidental or overly aggressive routing more likely. Because this skill targets proactive and self-improving workflows, ambiguous activation is more dangerous than for a passive utility skill: it may cause the agent to take initiative, change workflows, or generate artifacts in contexts where the user did not intend that behavior.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad, generic, and closely resemble normal user requests, which can cause the skill to activate in situations not specifically intended by the user. In an agent ecosystem, this increases the risk of accidental invocation, context hijacking, or the skill influencing unrelated workflows, especially because it targets proactive/self-improving behavior that may expand its operational scope.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes extremely generic terms such as "self," "improving," and "proactive," which are common in ordinary user requests and not specific to this skill’s intended domain. This can cause accidental invocation in unrelated contexts, leading the agent to apply the wrong workflow, over-collect context, or produce irrelevant or misleading outputs at scale.

Vague Triggers

High
Confidence
94% confidence
Finding
The skill description says to use the skill for broad categories like "work-productivity" and "practical workflow, artifact, checklist, analysis, or implementation support," which makes activation criteria ambiguous and expansive. In an agent system, this increases the chance that the skill is selected for many unrelated tasks, creating prompt-routing errors and potentially unsafe or low-quality assistance due to scope confusion.

Vague Triggers

High
Confidence
96% confidence
Finding
触发关键词包含“self”“improving”“proactive”“bug fix”等高度通用词,极易与普通对话重叠,导致技能在大量非目标场景下被误触发。误触发会让代理偏离用户真实意图,插入不必要的工作流、分析或自动化建议,扩大后续决策和执行面的风险。

Vague Triggers

Medium
Confidence
90% confidence
Finding
技能描述写法偏营销式和概括式,只说明‘当用户提出 work-productivity, self-improving-proactive-agent, self, improving, proactive’时使用,但没有清晰限定任务边界、优先级和适用/不适用情形。这会让路由器或代理在语义接近但不相关的请求上错误激活该技能,降低结果可靠性。

Vague Triggers

Medium
Confidence
94% confidence
Finding
触发说明列出关键词和示例触发句,但没有任何排除条件、冲突解决规则或负例,导致触发范围几乎不受约束。对于代理系统而言,这类宽松定义会增加错误路由、上下文污染和无关自动化介入的概率,尤其是在多技能环境中更明显。

Vague Triggers

Medium
Confidence
94% confidence
Finding
The default prompt and skill description use very broad, generic phrasing such as 'help me' and a wide set of trigger concepts, which increases the chance the skill will be invoked in contexts the user did not explicitly intend. Because implicit invocation is enabled, this ambiguity can cause accidental activation, unexpected behavior, or undesired prompt injection into unrelated workflows.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences and keywords are broad enough to match common phrases such as 'help me', 'practical workflow', 'self', and 'improving', which can cause the skill to activate for unrelated user requests. This creates routing confusion and may lead the agent to apply the wrong workflow, increasing the chance of irrelevant guidance, unintended actions, or prompt-scope hijacking through accidental invocation.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.