Back to skill

Security audit

Work Productivity Self Improving Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

The skill is a non-executable workflow helper, but its activation rules are so broad that it could be invoked for unrelated user requests.

Install only if you are comfortable with a broad workflow-helper skill that may be auto-selected for general productivity, bug-fix, or self-improvement phrasing. Prefer explicit invocation or narrower routing rules before enabling it in environments where unrelated tasks should not be steered into this workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentences are generic and map to common words like 'self', 'improving', and 'proactive', which can cause the skill to activate in contexts far beyond the intended use case. In an agent ecosystem, over-broad activation can misroute user requests, override more appropriate skills, and create prompt-injection or workflow-confusion opportunities by invoking this skill unexpectedly.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are extremely generic ('Help me', 'I need a practical workflow') and can match ordinary user requests unrelated to this skill, causing the agent to invoke the skill too broadly. In a self-improving/proactive workflow skill, overbroad activation increases the chance of unrequested behavior, context hijacking, or inappropriate workflow injection into normal conversations.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger list includes extremely generic terms such as 'self', 'improving', and 'proactive', which commonly appear in unrelated user requests. This can cause accidental invocation of the skill in contexts far outside its intended scope, increasing the chance of inappropriate workflow injection, user confusion, or unintended handling of sensitive tasks.

Vague Triggers

High
Confidence
93% confidence
Finding
The manifest description says to use the skill when a user asks for broad categories like 'work-productivity' or 'needs a practical workflow, artifact, checklist, analysis, or implementation support,' which are common across many benign requests. Without strong trigger constraints, the skill may be selected too broadly, leading to overreach, unintended prompt routing, and increased exposure of users to a self-improving/proactive workflow pattern in situations where it was not requested.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger list is excessively broad, including generic terms like 'self', 'improving', 'proactive', 'learning', and 'bug fix' that commonly appear in ordinary user requests. This can cause unintended skill activation, hijacking unrelated conversations and steering the agent into this workflow when the user did not explicitly request it.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says to use the skill when users mention broad themes or need 'practical workflow, artifact, checklist, analysis, or implementation support,' which is too ambiguous to reliably scope activation. In an agent system, vague invocation conditions increase accidental routing and make it easier for unrelated prompts to be captured by this skill.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The skill file is written in Chinese and does not offer a user-choice mechanism for language, which can force output into a locale the user did not request. While not a direct code-execution issue, it can degrade usability, cause misunderstanding of safety-critical guidance, and increase the chance of incorrect user action.

Vague Triggers

High
Confidence
95% confidence
Finding
The default prompt embeds a very broad invocation phrase tied to common terms like work productivity, self-improving, and practical help, which can cause the skill to activate in unrelated user conversations. In combination with agent routing, this increases the chance of prompt/context injection into ordinary workflows and unexpected execution of this skill without clear user intent.

Vague Triggers

High
Confidence
98% confidence
Finding
Enabling implicit invocation without clear activation constraints allows the platform to auto-select this skill based on vague similarity rather than explicit user consent. Because the skill is framed broadly and targets proactive/self-improving workflows, misrouting could expose unrelated user requests to unintended instructions or actions, making prompt-surface abuse and overreach more likely.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are so generic that they can match many normal requests involving productivity, self-improvement, or proactive help, causing the skill to activate outside its intended scope. This creates a routing and prompt-injection surface where users may be funneled into an irrelevant or overly powerful workflow, increasing the chance of unsafe automation, confusion, or misuse in downstream tasks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.