Back to skill

Security audit

Work Productivity Self Improving Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overbroad activation wording but no hidden execution, persistence, credential use, or destructive behavior.

Installers should be aware that the skill may be invoked too easily because its trigger terms are broad. Prefer explicit invocation by skill name for this helper, and consider tightening the keywords before publishing broadly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence is broad and resembles normal user language, which can cause the skill to activate when a user is making a general request rather than explicitly intending to invoke this workflow. In agent ecosystems, unintended invocation can route tasks into the wrong workflow, causing inappropriate automation, confusing outputs, or unsafe chaining with other proactive/self-improving behaviors.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The invocation guidance lists keywords and sample trigger sentences but does not define when the skill must not activate, leaving boundaries ambiguous. For a proactive/self-improving workflow skill, ambiguous routing increases the chance of accidental activation on generic terms like 'self', 'improving', or 'proactive', potentially leading an agent to overreach, mis-handle user intent, or initiate unnecessary workflow steps.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger examples are broad natural-language prompts that could match many ordinary user requests, causing the skill to activate outside its intended scope. In an agentic workflow skill, overbroad activation increases the chance of unintended prompt injection surface expansion, user confusion, and inappropriate workflow execution on unrelated tasks.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keyword list includes extremely broad terms such as 'self', 'improving', and 'proactive', which are common in ordinary conversation and likely to cause unintended skill activation. In an agent environment, this can silently route unrelated user requests into this skill, creating prompt-scope confusion, workflow hijacking, or unsafe overreach if the skill then drives planning or code-change behavior beyond the user's intent.

Vague Triggers

High
Confidence
92% confidence
Finding
The description says to use the skill when a user asks for broad categories like 'work-productivity' or 'self', which creates ambiguous invocation criteria with weak boundaries. This increases the chance that the skill is selected for loosely related requests, causing unintended instruction injection into unrelated tasks and making agent behavior less predictable or controllable.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The example trigger sentences are generic and repeat broad phrases like 'need practical help' without clear boundaries, which trains invocation systems or maintainers toward overmatching. While not directly executable, this expands the effective trigger surface and can cause accidental routing of commonplace requests into a skill that may then produce unnecessary planning or automation guidance.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes extremely broad everyday terms such as "self", "improving", "proactive", "learning", and "bug fix", which are likely to match many unrelated user requests. This can cause unintended skill activation, leading the agent to apply the wrong workflow, override more appropriate skills, or inject irrelevant instructions into benign tasks.

Vague Triggers

High
Confidence
94% confidence
Finding
The description says to use the skill whenever a user asks for broad concepts like work-productivity, self, improving, or proactive, or generally needs practical workflow or analysis support. These activation conditions are ambiguous and expansive, making accidental invocation likely across many normal conversations and increasing the chance of misrouting tasks or unintended agent behavior.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation with a very broad description and generic trigger language, which can cause the agent to activate in contexts the user did not clearly intend. This increases the risk of unexpected prompt injection surface expansion, inappropriate tool selection, or the skill influencing workflows outside its intended scope.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentence is excessively broad and reads like ordinary user language, which can cause the skill to activate in situations far outside its intended scope. In an agent system, unintended activation can misroute tasks, override more appropriate skills, and create confused-deputy style behavior where the agent applies this workflow to unrelated requests.

Vague Triggers

Medium
Confidence
93% confidence
Finding
This trigger remains too generic and lacks constraints that distinguish eligible requests from normal conversation, increasing the chance of accidental or excessive routing to this skill. Because the skill is framed as broadly helping with workflows, reliability, fixes, and adjacent tasks, ambiguous activation could expand its reach into many unrelated prompts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.