Back to skill

Security audit

Work Productivity Self Improving Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable workflow-helper skill with overly broad activation wording, but no hidden code, persistence, credential use, or destructive behavior.

Before installing, consider narrowing or disabling implicit activation if you only want this skill used for explicit self-improving or proactive-agent workflow requests. The skill appears safe as a prompt/template helper, but its generic trigger terms may make it appear in unrelated productivity conversations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad, generic, and overlap with common user language such as 'help me', 'practical workflow', and terms like 'self', 'improving', or 'proactive'. This can cause unintended skill activation in unrelated conversations, leading the agent to apply the wrong workflow, leak context into an unnecessary skill path, or override more appropriate skills.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases include extremely generic terms like 'self', 'improving', and 'proactive', which can match a wide range of unrelated everyday requests. This can cause the skill to activate unintentionally, broadening its authority and increasing the chance of misrouting user requests into a more autonomous or self-modifying workflow than intended.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger list includes extremely generic terms such as "self," "improving," and "proactive," which are common in ordinary user requests and likely to cause unintended skill activation. This can route unrelated conversations into this skill, creating prompt-scope confusion and increasing the chance the agent applies inappropriate workflows or exposes unnecessary internal behavior.

Vague Triggers

High
Confidence
94% confidence
Finding
The description says to use the skill when a user asks for broad concepts like "work-productivity," "self," "improving," or "proactive," which makes invocation boundaries ambiguous. Ambiguous routing is dangerous because it can cause accidental selection of this skill in unrelated contexts, leading to misapplied automation guidance and reduced reliability of agent behavior.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger list includes very broad everyday terms such as "self", "improving", and "proactive", which can match many unrelated user requests and cause accidental activation. In an agent system, over-broad invocation can route conversations into the wrong workflow, producing irrelevant actions, increased autonomy where not intended, and possible policy or safety bypass via misclassification.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The description says the skill should be used when users ask for broad categories like work-productivity, self, improving, or proactive, without clearly defining scope boundaries. This makes the activation surface overly large and ambiguous, increasing the chance that unrelated requests are captured and handled by a workflow that may make assumptions or produce actions the user did not intend.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation while using a very broad name, description, and default prompt centered on generic productivity and self-improvement assistance. This increases the chance the platform auto-selects the skill for ordinary user requests beyond the author's intended scope, causing unexpected behavior, prompt-surface expansion, or unintended execution paths. The context makes this more dangerous because the skill is framed as broadly useful for many adjacent tasks, which further widens matching ambiguity.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence begins with a highly generic phrase ('Help me'), which can cause the skill to activate on ordinary user requests that are not specifically about this skill’s intended workflow. In an agent ecosystem, overly broad activation increases the chance of accidental invocation, prompt-routing confusion, and misuse of the skill in contexts where its assumptions do not apply.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The sentence 'I need a practical workflow for ...' is a broadly generic request pattern that overlaps with many benign productivity requests, making unintended matching likely. Because this skill is framed as broadly applicable workflow help, generic trigger text further widens activation scope and can lead to incorrect tool selection or overreach by an agent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.