Back to skill

Security audit

Work Productivity Self Improving Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but it does not contain hidden execution, credential access, persistence, or data exfiltration behavior.

Before installing, be aware that this skill may be selected for broad productivity, bug-fix, or self-improvement wording. It appears safe as an advisory workflow helper, but users who want tighter routing should narrow the trigger terms or disable implicit invocation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are generic and can match many unrelated user requests, increasing the chance the skill activates outside its intended scope. In an agentic workflow, over-broad activation can cause unintended delegation, confusing behavior, or application of self-improving/proactive patterns where they were not requested, which is a security and reliability risk even without explicit malicious content.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger keywords and example invocations are very broad, including generic terms like 'self', 'improving', and 'proactive', which can cause the skill to activate in unrelated contexts. In an agent ecosystem, unintended activation can redirect workflows, override more appropriate skills, or cause the agent to apply self-modification or workflow-changing behavior where the user did not intend it.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords include extremely common terms like 'self', 'improving', and 'proactive', which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance that this skill intercepts requests outside its intended scope, leading to prompt-routing errors, unintended instruction injection surface, and reduced predictability of agent behavior.

Vague Triggers

High
Confidence
93% confidence
Finding
The manifest description says to use the skill when a user asks for broad categories like 'work-productivity' or generic workflow help, making invocation criteria ambiguous and expansive. In agent systems, this can misroute many unrelated tasks into this skill, which is dangerous because broad skill capture can override more appropriate tools and amplify any unsafe or irrelevant guidance.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger phrases are generic and templated, so they do not establish meaningful boundaries for safe invocation. Weak examples train matching systems and authors toward broad routing behavior, which increases accidental activation and reduces confidence that the skill will only run for relevant self-improving agent workflow tasks.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords include extremely broad everyday terms like “self”, “improving”, and “proactive”, which can match many unrelated user requests and cause the skill to activate unexpectedly. Over-broad activation increases the chance that this skill intercepts prompts outside its intended scope, leading to confusing behavior, inappropriate workflow injection, or accidental priority over more relevant skills.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description defines activation conditions so broadly that many generic productivity or implementation-support requests could match, even when the user did not intend to invoke this specific skill. This creates ambiguous routing boundaries and can make the agent apply the skill in unrelated contexts, reducing reliability and potentially interfering with safer or more appropriate skills.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation without any visible trigger constraints, which can cause the agent to activate this skill in situations the user did not clearly intend. Because this skill is framed broadly around proactive/self-improving workflows, ambiguous auto-selection increases the chance of overreach, unintended actions, or inappropriate influence on unrelated tasks.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases are generic enough to match many ordinary requests, which can cause the skill to activate outside its intended scope. In an agent ecosystem, over-broad routing can steer users into irrelevant or misleading workflows, increase prompt-surface exposure, and make later controls less reliable because the skill is invoked for ambiguous intents.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.