Back to skill

Security audit

Work Productivity Self Improving Workflow Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation language but no evidence of hidden execution, data access, persistence, or destructive behavior.

Before installing, be aware that this skill may be selected for broad productivity or bug-fix requests more often than intended. Its behavior is otherwise limited to producing plans, checklists, analysis, and implementation guidance.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Vague Triggers

High
Confidence
94% confidence
Finding
The description says to use the skill whenever a user asks for broad categories like work-productivity, proactive behavior, practical workflows, checklists, analysis, or implementation support. That scope is so expansive that it overlaps with many unrelated tasks, increasing the chance of accidental routing and over-application of the skill.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes extremely generic terms such as "self," "improving," "proactive," and "bug fix," which are common in ordinary user requests. This makes unintended invocation likely, causing the wrong skill to activate and potentially steer conversations into autonomous or self-modifying workflow guidance when the user did not request it.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords include very broad everyday terms such as “self”, “improving”, and “proactive”, which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance of prompt/context hijacking at the routing layer, unwanted instruction injection into benign tasks, and unpredictable workflow selection that may override more appropriate skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger sentences and keywords are broad enough to match many ordinary requests unrelated to this skill’s specific requirement. That can cause unintended invocation, routing confusion, and over-application of the skill in contexts where it was not explicitly requested, increasing the chance of inappropriate automation or misleading outputs.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger examples are phrased as generic help requests rather than narrowly scoped invocations, which can cause the skill to activate on ordinary user language unrelated to this specific workflow. In an agent environment, that increases the chance of unintended routing, prompt capture, and execution of the wrong skill, especially because the skill presents itself as broadly applicable to bug fixing, safety hardening, and workflow support.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The trigger phrases are broad, generic, and semantically close to ordinary productivity/help requests, which can cause the skill to activate in contexts the user did not clearly intend. In an agent ecosystem, overbroad invocation increases the chance of prompt-shadowing or unintended workflow takeover, potentially steering unrelated tasks into this skill’s behavior and outputs.

Natural-Language Policy Violations

Medium
Confidence
85% confidence
Finding
The file descriptions explicitly label separate English and Chinese documents, and the current README is a Chinese-localized variant, but there is no natural-language statement offering the user a language choice or opt-in. Under the stated policy, forcing a locale without user selection can be a language/locale policy violation.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example triggers are phrased like normal help requests and do not contain a clear, distinctive invocation pattern. As a result, they train matching systems or operators to treat ordinary language as a signal to activate the skill, increasing false activations and unintended behavior.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description defines activation conditions in broad, ambiguous terms like requests related to work-productivity or practical support, without clear boundaries for when the skill should or should not be used. This ambiguity can cause accidental invocation and misrouting, which weakens safety controls and reduces predictability of agent behavior.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases are generic and repetitive, and they do not include counterexamples showing non-triggering cases. Without negative examples, routing systems and maintainers have little guidance for distinguishing valid invocations from incidental mention of related concepts, increasing false positives and unsafe over-application.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt contains broad, everyday phrases such as 'help me' and generic productivity language that can match many unrelated user requests. In combination with a skill designed for proactive/self-improving workflows, this increases the chance of over-invocation, unintended context capture, and the skill being inserted into conversations where it was not explicitly requested.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without clear trigger constraints allows the platform to auto-select this skill for loosely related prompts. Because the skill description is expansive and overlaps with common workplace assistance requests, this raises the risk of unintended activation, prompt-scope creep, and interference with other skills or baseline model behavior.

Natural-Language Policy Violations

Low
Confidence
77% confidence
Finding
Several evidence entries contain Chinese-language titles, but the document provides no indication that multilingual or locale-specific content is optional or user-selected. This creates a mild language-policy concern because the file mixes languages without documenting user choice or regional justification.

Static analysis

No suspicious patterns detected.