Back to skill

Security audit

Work Productivity Self Improving Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation language, but no hidden code, data access, persistence, or destructive behavior.

Install only if you want a general workflow helper for self-improving or proactive agent work. Be aware that its broad trigger words may make it appear for loosely related requests, so review the selected skill when precision matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger examples are broad, generic, and closely resemble common user requests, which increases the chance of accidental or over-eager activation in contexts the user did not explicitly intend. In a self-improving/proactive workflow skill, unintended activation is more concerning because the skill may steer planning, reflection, or workflow decisions beyond the user's narrow request.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are broad, generic, and include common terms like "self", "improving", "proactive", and broad natural-language prompts that can match ordinary user requests unrelated to this skill. In an agent/skill-routing system, this can cause unintended invocation, prompt hijacking of benign tasks into this workflow, and unreliable behavior that expands the skill's reach beyond user intent.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description is so broad that it can match many ordinary user requests unrelated to a narrowly scoped capability. Over-broad activation increases the chance this skill is invoked unexpectedly, causing instruction collisions, unintended behavioral overrides, and making prompt-injection or policy-conflict issues easier to surface in unrelated contexts.

Vague Triggers

High
Confidence
99% confidence
Finding
The keyword list includes vague single-word triggers such as 'self', 'improving', and 'proactive' that are common in benign conversation. This makes accidental invocation highly likely and can let the skill intercept broad classes of requests, increasing the attack surface for misrouting, instruction interference, and unintended autonomy patterns.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The example trigger sentences use broad natural language that mirrors ordinary user phrasing without defining concrete activation boundaries. That trains or encourages activation on loosely related requests, which can cause the skill to engage outside its intended context and override more appropriate handling.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords include very broad everyday terms such as "self", "improving", and "proactive", which can match many unrelated user requests. This can cause the skill to activate unexpectedly and override more appropriate skills or workflows, creating unsafe or irrelevant automation behavior.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description defines applicability in very broad terms, covering generic productivity and implementation support requests without clear exclusion boundaries. Overbroad scope increases the chance of accidental invocation in contexts the skill was not designed for, which can lead to poor guidance, unintended actions, or interference with safer specialized skills.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt includes a very broad natural-language trigger phrase covering common terms like 'work-productivity', 'self', 'improving', and 'practical help', which can cause unintended implicit invocation during ordinary user conversations. Because implicit invocation is enabled, this increases the chance that the skill activates without clear user intent, potentially inserting workflow guidance or agent behavior into unrelated contexts.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentences are extremely broad and overlap with ordinary user phrasing such as 'help me' and 'I need a practical workflow,' which can cause the skill to activate in contexts where the user did not intend to invoke it. In an agent ecosystem, unintended invocation can misroute tasks, override more appropriate skills, and increase the chance of unsafe or irrelevant automated actions being taken under the wrong workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.