Back to skill

Security audit

Work Productivity Self Improving Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with overly broad activation wording, but no hidden code, credential use, persistence, or destructive behavior.

Installers should be aware that this skill may be selected for ordinary requests containing broad words like self, improving, errors, or bug fix. Prefer explicit invocation by skill name or narrow its activation rules before enabling implicit invocation in shared or sensitive agent environments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are extremely broad and use common language like 'Help me' and 'I need a practical workflow,' which can cause the skill to activate in many unrelated contexts. In an agent ecosystem, overly permissive activation increases the chance of unintended invocation, context hijacking, or routing sensitive user requests into a workflow the user did not explicitly intend to use.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keywords and example invocations are extremely broad, including generic terms like 'self', 'improving', 'errors', and 'bug fix' that commonly appear in unrelated user requests. This can cause the skill to activate unintentionally, leading to prompt hijacking of normal conversations, unexpected workflow injection, and unreliable routing behavior across many benign tasks.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger list includes extremely broad everyday terms such as "self" and "improving," which can match many unrelated user requests and cause accidental skill invocation. In an agent ecosystem, over-broad activation can route sensitive or irrelevant tasks into the wrong workflow, increasing the chance of unsafe automation, prompt contamination, or unintended tool use.

Vague Triggers

High
Confidence
95% confidence
Finding
The description says to use the skill when a user asks for broad concepts like "work-productivity," "self," or "improving," which ambiguously defines activation scope. This makes the skill eligible for a wide range of unrelated conversations, creating misrouting risk and making downstream agent behavior less predictable and less safe.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger sentences are repetitive and generic, and they do not distinguish this skill from many other productivity or workflow requests. Vague examples train users or orchestrators to invoke the skill without meaningful boundaries, which reinforces accidental activation caused by the already over-broad description and keyword set.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keyword list includes extremely broad everyday terms such as "self", "improving", "enable", and "bug fix", which can match many unrelated user requests and cause accidental activation. Overbroad invocation increases prompt-surface exposure, can route conversations into an unintended workflow, and may lead to irrelevant or unsafe automation being applied without clear user intent.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description says it should be used when users ask for broad concepts like work-productivity, self, improving, or practical support, without defining meaningful boundaries. This can cause the skill to claim relevance for a wide range of ordinary requests, increasing accidental triggering and making downstream behavior less predictable.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The example trigger phrases are broad and repetitive, and they do not show negative examples or boundary cases. In practice this teaches the router or operator to activate the skill from loosely related language, reinforcing over-triggering and reducing confidence that invocation reflects actual user intent.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt contains a very broad activation phrase tied to common terms like 'work-productivity' and 'self-improving', which can overlap with ordinary user requests. This increases the chance of unintended skill invocation, causing the agent to inject this skill's behavior into unrelated conversations and potentially override user intent or introduce unsafe workflow changes.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without tight activation boundaries allows the skill to be selected automatically in ambiguous contexts. In a skill focused on self-improving workflows, unintended activation is more dangerous because it may influence agent configuration, reliability, or safety-related behavior without deliberate user consent.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences are extremely broad and include generic phrases like 'Help me' and 'I need a practical workflow' tied to a long requirement description. In practice, this can cause the skill to activate for many unrelated user requests, creating prompt-routing confusion, overshadowing more appropriate skills, and increasing the chance that users are steered into unintended workflows.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The keyword list and activation guidance are ambiguous, using broad terms such as 'self', 'improving', and 'captures' that are common in everyday conversation. This makes the skill's activation boundary unclear, which can lead to accidental invocation, misclassification of user intent, and reduced safety because unrelated requests may be processed under the wrong workflow assumptions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.