Back to skill

Security audit

Work Productivity Self Improving Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with overly broad activation prompts but no hidden code, credential access, persistence, or destructive behavior.

Before installing, consider narrowing or explicitly invoking this skill because its generic trigger words may activate it during unrelated workflow or productivity conversations. The inspected package otherwise appears to be a low-risk documentation helper.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are broad and overlap with common words like 'self', 'improving', and 'proactive', which can cause the skill to activate in contexts far beyond its intended scope. In an agent ecosystem, overly permissive activation can route unrelated user requests into this workflow, leading to confused execution, unintended actions, or unsafe delegation to a skill that is not context-appropriate.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger phrases are broad and generic, including common terms like "self", "improving", and "proactive", which can cause the skill to activate in unrelated conversations. In an agent environment, this increases the chance of unintended invocation, context hijacking, or the skill influencing workflows when the user did not explicitly request it.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes extremely broad terms like "self," "improving," and "proactive," which are common in ordinary conversation and likely to cause unintended activation. Over-broad activation can route unrelated user requests into this skill, creating prompt-scope confusion and increasing the chance the agent applies the wrong workflow or discloses irrelevant internal process guidance.

Vague Triggers

High
Confidence
91% confidence
Finding
The manifest description says to use the skill whenever a user asks for broad categories like work-productivity or practical workflow help, without defining exclusion criteria or clear scope limits. This ambiguity increases accidental invocation and can make the system select this skill over more appropriate ones, reducing reliability and weakening user intent isolation.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger phrases are generic requests for "practical workflow" help and closely resemble normal user language, which reinforces loose matching behavior. While not directly exploitable as code execution, they increase the chance of misrouting and unintended skill activation in benign conversations.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes extremely broad, everyday terms such as "self", "improving", and "proactive", which can cause the skill to activate in many unrelated conversations. Overbroad activation increases the chance of unintended skill invocation, context hijacking, and inappropriate workflow steering, especially because this skill is framed as generally applicable process help rather than a narrowly bounded function.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The invocation description says to use the skill when users mention broad concepts like work productivity, self, improving, or proactive, without clearly distinguishing this skill from many ordinary requests. This ambiguity can cause accidental routing to the skill, leading to irrelevant instructions, reduced predictability, and possible interference with safer or more appropriate skills.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt includes broad, natural-language trigger terms like 'help me' and generic work/productivity phrasing, while implicit invocation is enabled. This can cause the skill to activate in ordinary conversations unrelated to the user's intent, increasing the chance of prompt hijacking, unintended tool routing, or exposure of the skill's behavior in inappropriate contexts.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentences are broad enough to match ordinary user phrasing such as requests for practical workflows, help, or implementation support. In a skill-routing system, this can cause unintended activation and prompt capture, leading the agent to invoke this skill when the user did not explicitly intend it, which increases the chance of irrelevant actions or unsafe workflow substitution.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.