Back to skill

Security audit

Work Productivity Self Improving Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

The skill is text-only and shows no malicious behavior, but its automatic invocation is too broad and could affect unrelated user requests.

Review this before installing if your environment allows implicit skill invocation. It is best used only when explicitly requested for self-improving or proactive agent workflow design; otherwise it may be selected for ordinary productivity, learning, or bug-fix prompts where a narrower skill would fit better.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentences and keywords are broad enough that the skill may activate for vague terms like 'self', 'improving', or 'proactive' outside the intended context. This can cause unintended invocation, prompt-routing errors, or over-application of the skill to unrelated user requests, which is risky in agentic workflows because it can steer behavior or outputs unexpectedly.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad, generic, and map to common terms like 'self', 'improving', 'proactive', and 'bug fix', which can cause the skill to activate for many unrelated user requests. In an agent ecosystem, this increases the chance of unintended invocation, context hijacking, or the skill influencing workflows it was not explicitly selected for.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keywords are extremely broad, including common words like 'self', 'improving', and 'proactive', which are likely to appear in ordinary conversation unrelated to this skill. This can cause unintended skill activation, override more appropriate skills, and expand the attack surface for prompt-routing abuse or accidental execution in benign contexts.

Vague Triggers

High
Confidence
96% confidence
Finding
The description says to use the skill when a user asks for broad categories like 'work-productivity', 'self', 'improving', or any practical workflow/artifact/checklist support, making invocation criteria so expansive that many unrelated requests could match. In an agent environment, this ambiguity can route sensitive or irrelevant tasks into this skill unexpectedly, leading to privilege confusion, unreliable behavior, and increased susceptibility to prompt-trigger collisions.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The example trigger phrases are framed as generic help requests and repeat broad language that could easily occur in ordinary user prompts. These examples reinforce weak routing rules and make accidental or adversarial invocation more likely, especially in systems that learn or infer trigger patterns from examples.

Vague Triggers

High
Confidence
96% confidence
Finding
触发关键词包含“self”“improving”“proactive”等高度通用词汇,会让技能在大量无关对话中被意外触发,扩大技能介入面。对一个会生成流程、分析、代码修改建议的技能来说,误触发可能覆盖更合适的技能选择,导致错误自动化、误导性输出或不必要暴露上下文。

Vague Triggers

Medium
Confidence
90% confidence
Finding
技能描述把启用条件写成一组宽泛主题和“需要实用流程、产物、检查清单、分析或实现支持”这类泛化表述,边界不清晰。结果是调度器或使用者难以判断何时真正适用该技能,增加误选和过度匹配的概率。

Vague Triggers

Medium
Confidence
88% confidence
Finding
示例触发句全部是正向示例,且措辞重复需求文本,没有展示哪些相似请求不应触发该技能。这会放大模糊描述和宽泛关键词的问题,使集成方更容易把普通求助也路由到该技能。

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt contains a very broad activation phrase tied to generic concepts like work productivity, self-improving, and practical help, which overlap with common user language. In systems that support prompt-based routing or invocation, this can cause accidental or excessive triggering of the skill, leading to unintended handling of user requests and increasing the chance of prompt-scope confusion or policy bypass through over-invocation.

Vague Triggers

High
Confidence
97% confidence
Finding
Enabling implicit invocation without strong activation constraints allows the skill to be selected automatically for loosely related user requests. Because this skill is framed around proactive and self-improving workflows, unintended activation is more dangerous here: it can insert broad workflow guidance or take on decision-making roles in contexts the user did not explicitly request, expanding attack surface and increasing the risk of unsafe or manipulative behavior.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentences are phrased in broad, natural language that overlaps with ordinary user requests, which can cause the skill to activate when a user did not explicitly intend to invoke it. In an agent environment, unintended invocation can misroute tasks, override more appropriate skills, and increase the chance of irrelevant or unsafe autonomous behavior due to scope confusion.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.