Back to skill

Security audit

Work Productivity Self Improving Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording but no hidden execution, data access, persistence, or destructive behavior.

Safe to install if you want a lightweight workflow helper, but expect it may be invoked too easily for generic productivity or bug-fix requests; narrowing triggers or disabling implicit invocation would make it cleaner.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentences and keywords are broad enough that the skill may activate for generic requests involving 'self', 'improving', 'logs', or 'bug fix', even when the user did not intend to invoke this specific workflow. In an agent ecosystem, overly permissive invocation can cause misrouting, unintended execution of workflow instructions, or inappropriate access to contextual artifacts, reducing reliability and potentially exposing sensitive task context to the wrong skill.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger examples are generic enough to match ordinary user requests like asking for help with bug fixes or practical workflows, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance that the agent applies this workflow in irrelevant contexts, leading to prompt hijacking of user intent, accidental tool use, or unexpected disclosure of internal process patterns.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords are excessively broad, including generic terms like 'self', 'improving', and 'logs' that commonly appear in unrelated conversations. This can cause accidental invocation or routing of the skill in contexts far outside its intended scope, increasing the chance that users receive inappropriate workflow guidance or that higher-priority skills are bypassed.

Vague Triggers

High
Confidence
93% confidence
Finding
The description encourages use for broad categories like 'work-productivity' and 'needs a practical workflow, artifact, checklist, analysis, or implementation support,' which are common across many benign requests. Without clear scope constraints, the skill may be selected for tasks it was not designed to handle, creating misrouting risk and weakening prompt/skill isolation.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger sentences use vague, everyday phrasing such as 'Help me' and 'I need a practical workflow,' which normalizes invocation patterns that are not sufficiently specific to this skill. This increases the likelihood of overmatching in natural-language routing systems and may lead to unnecessary or incorrect activation.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keyword list includes very broad everyday terms such as "self", "improving", and "own", which can cause the skill to activate for many unrelated requests. Over-broad activation can route users into the wrong workflow, leading to unintended instruction injection into unrelated tasks, confusion, and reduced reliability of the agent system.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The description says the skill should be used when users mention broad concepts like work-productivity, self, improving, or logs, without clear boundaries. This ambiguity increases accidental invocation risk and can cause the skill to intercept unrelated conversations, especially in systems that auto-select skills based on metadata.

Vague Triggers

High
Confidence
95% confidence
Finding
The default prompt is phrased broadly enough to match common user language about productivity, workflows, logs, or implementation help, which can cause the skill to activate in situations the user did not clearly intend. In a self-improving workflow skill, unintended activation is especially risky because the skill may steer conversations, consume context, or influence agent behavior across many routine requests.

Vague Triggers

High
Confidence
97% confidence
Finding
Enabling implicit invocation without clear scope boundaries allows the platform to auto-select this skill for a wide range of ambiguous requests. Because this skill is framed as a self-improving workflow helper, accidental invocation could let it affect troubleshooting, reliability, safety, or adjacent-skill generation tasks more broadly than intended, increasing the chance of prompt-surface expansion and unwanted behavioral influence.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences are written in broad, natural language that overlaps with ordinary user requests, which can cause the skill to activate when the user did not explicitly intend to invoke it. In an agent system, unintended invocation can misroute tasks, override more appropriate skills, and increase the chance of unsafe or irrelevant automation being applied without clear user consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.