Back to skill

Security audit

Work Productivity Self Improving Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with overly broad activation wording but no hidden code, persistence, credential handling, or destructive behavior.

Installers should be aware that the skill may be invoked for broad productivity or self-improvement language. Prefer explicit invocation when possible and review any suggested workflow or code-change plan before acting on it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentences are broad natural-language requests that could match ordinary user prompts unrelated to this specific skill, causing the agent to invoke the skill unexpectedly. In a self-improving/proactive workflow context, accidental activation is more concerning because the skill may steer planning, workflow changes, or follow-on actions without the user explicitly selecting it.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are generic enough to match ordinary requests containing words like 'self', 'improving', or 'proactive', which can cause the skill to activate outside its intended scope. In a self-improving/proactive workflow skill, unintended activation is more dangerous because it may steer unrelated conversations into autonomous or workflow-changing behavior the user did not explicitly request.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes extremely broad terms like 'self', 'improving', 'proactive', 'learning', and 'organizing', which are common in ordinary user requests. This can cause the skill to activate unintentionally for unrelated conversations, creating prompt-scope confusion and increasing the chance that the wrong workflow or instructions are applied.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation description says to use the skill when a user asks for broad categories like 'work-productivity', 'self', 'improving', or 'proactive', which does not clearly delimit the intended operating context. This ambiguity can lead to over-invocation, misrouting, and accidental application of the skill to requests outside its intended domain.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords include extremely broad everyday terms such as "self", "improving", and "proactive", which can match many unrelated user requests and cause the skill to activate unintentionally. Over-broad activation increases the chance of prompt-context hijacking, incorrect tool selection, and inappropriate insertion of this workflow into unrelated tasks.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description defines activation conditions very broadly, covering vague concepts like work-productivity, self, improving, and proactive, without meaningful boundaries. This makes accidental invocation likely and can route unrelated requests into a skill that may steer the agent’s behavior or outputs in unintended ways.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The example trigger phrases are close to ordinary help-seeking language and do not establish clear calling boundaries. Such examples can bias matching systems or authors toward invoking the skill for generic assistance rather than for the narrowly intended workflow-improvement use case.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt is very broad and uses common, everyday language about productivity and practical help, which increases the chance the platform will invoke this skill unintentionally during unrelated user requests. Because the skill is framed as proactive and self-improving, accidental activation could cause unexpected workflow changes, inappropriate tool use, or user confusion about why the skill was engaged.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without clear constraints allows the skill to be selected automatically based on loose semantic matches rather than deliberate user intent. In a skill centered on proactive, self-improving workflows, this makes unintended activation more dangerous because the skill may influence actions, recommendations, or process changes without sufficiently explicit consent.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is phrased so broadly that ordinary user requests containing common terms like 'help me' or generic workflow language could unintentionally activate the skill. In an agent ecosystem, overbroad invocation can cause the wrong skill to run, leading to confusing behavior, scope creep, or unsafe automation being applied outside the intended context.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger guidance is ambiguous and lacks clear activation boundaries, so routing logic may match this skill for loosely related requests about productivity, self-improvement, or proactive help. That increases the chance of unintended invocation, which is especially risky for a self-improving/proactive agent workflow because such skills may take broad action or shape downstream decisions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.