Back to skill

Security audit

Work Productivity Self Improving Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with overly broad activation wording, but it does not request sensitive access, persistence, or hidden execution.

Before installing, be aware that this skill may activate for some unrelated productivity or self-improvement requests. Use explicit skill naming when you want it, and review outputs normally before applying any generated workflow or code change.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are very broad and include generic terms such as 'self', 'improving', and 'proactive', which can cause the skill to activate in many unrelated contexts. In an agent ecosystem, overly permissive activation can route user requests to the wrong skill, leading to inappropriate workflow execution, confusion, or accidental handling of tasks outside the skill's intended scope.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger phrases are broad, generic, and include common words like 'help me', 'practical workflow', and 'practical help', which can cause the skill to activate for unrelated everyday requests. In an agent ecosystem, over-broad invocation increases the chance of unintended routing, context capture, or the skill influencing tasks outside its intended scope.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes extremely generic terms like "self," "improving," and "proactive," which are common in ordinary user requests. This can cause the skill to activate far outside its intended scope, leading to prompt hijacking of unrelated tasks, degraded routing accuracy, and unintended exposure of this skill's instructions in benign conversations.

Vague Triggers

High
Confidence
93% confidence
Finding
The description says to use the skill for broad categories like "work-productivity" and "practical workflow, artifact, checklist, analysis, or implementation support," which are expansive enough to match many unrelated requests. This ambiguity increases the chance of over-selection, causing the agent to apply this skill in contexts it was not designed for and potentially interfere with safer or more appropriate skills.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very broad everyday terms such as "self", "improving", and "proactive", which can match many unrelated user requests and cause accidental activation. Over-broad auto-triggering can route conversations into the wrong skill, leading to irrelevant guidance, prompt-scope confusion, and increased exposure to any risky behaviors embedded in the skill.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says to use the skill when users ask for broad themes like work-productivity, self, improving, or proactive, without clearly defining boundaries. This ambiguity increases the chance of unintended invocation and mismatched assistance, especially in systems that select skills automatically from natural-language descriptions.

Vague Triggers

High
Confidence
96% confidence
Finding
The default prompt contains a very broad activation phrase tied to common concepts like work productivity, self-improving, and practical help, which are likely to appear in ordinary user requests. This increases the chance of unintended routing or silent invocation, causing the skill to engage outside the user's explicit intent and potentially influence responses in unrelated contexts.

Vague Triggers

High
Confidence
98% confidence
Finding
Enabling implicit invocation without tightly scoped triggers or exclusions allows the skill to be auto-selected for a wide range of normal conversations. In this skill's context, which is framed around proactive and self-improving workflows, unexpected activation is more dangerous because it can steer behavior, inject workflow guidance, or alter agent actions without a clear user request.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is broad enough that ordinary user requests containing generic phrases like 'help me' and 'practical help' could activate the skill unintentionally. In an agent-routing system, this can cause misselection, prompt-surface expansion, and unintended execution of workflow logic on unrelated tasks, which is a real control-plane security and reliability issue.

Vague Triggers

Medium
Confidence
90% confidence
Finding
This trigger is ambiguous because it does not clearly define when the skill should activate versus when a general productivity assistant should respond. Such ambiguity increases the chance of accidental invocation, incorrect tool selection, and privilege or context exposure to a skill that was not the user's intended target.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.