Back to skill

Security audit

Work Productivity Self Improving Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a workflow/documentation skill with overly broad activation wording, but it does not contain hidden execution, credential handling, persistence, or exfiltration behavior.

Installers should be aware that the skill may activate on generic requests about improvement, logs, or bug fixes. Prefer explicit invocation or narrower routing rules if available; otherwise review whether its planning workflow is appropriate before letting it guide code or skill changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger examples are broad enough to match ordinary phrases like 'help me' or 'I need a practical workflow,' which can cause the skill to activate in contexts the user did not explicitly intend. In an agent ecosystem, this increases the chance of unintended routing, over-privileged execution paths, or user confusion about why this skill was selected.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger examples are broad enough to match ordinary user requests such as asking for help, workflows, bug fixes, or improvements, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad activation increases the chance of unintended delegation, prompt hijacking of generic tasks, and user confusion about which skill is acting.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes extremely generic terms such as 'self', 'improving', 'logs', 'own', and 'improved', which are common in normal conversations and likely to cause accidental skill activation. Over-broad activation can route unrelated user requests into this skill, creating prompt-scope confusion, unintended instruction injection surface, and unreliable agent behavior.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The description says to use the skill whenever a user asks for broad concepts like 'work-productivity', 'self', 'improving', or 'logs', without defining meaningful boundaries. This weak scoping increases unintended invocation risk and makes it easier for unrelated prompts to be interpreted as matching this skill.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example triggers model activation on vague natural-language requests rather than requiring specific intent or context. In practice, these examples train downstream systems or authors to invoke the skill too broadly, increasing accidental use and reducing separation between unrelated tasks.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes very broad everyday terms such as "self", "improving", "logs", "own", and "findings", which can match many unrelated user requests and cause accidental activation. Over-broad invocation increases the chance that this skill intercepts prompts outside its intended scope, leading to unintended workflow steering, confusion, or unsafe delegation in contexts where the skill is not appropriate.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The description says to use the skill when a user asks for broad categories like work-productivity, self, improving, or logs, without defining meaningful scope limits. This ambiguity can cause the routing system or operator to apply the skill to loosely related requests, making behavior unpredictable and increasing the risk of irrelevant or misleading assistance.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt contains broad, natural-language trigger terms such as 'help me' and generic productivity wording, which can cause the skill to be invoked in many unrelated contexts. Because implicit invocation is enabled, this increases the chance of accidental routing, prompt confusion, or untrusted skill activation when users make ordinary requests.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentences and keywords include broad, common terms such as "self," "improving," "logs," and generic request phrasing like "Help me" and "I need a practical workflow," which can cause the skill to activate for many unrelated user requests. This increases the chance of unintended invocation, misrouting, or prompt-surface expansion where irrelevant or attacker-crafted inputs steer the agent into using this skill outside its intended scope.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.