Back to skill

Security audit

Work Productivity Self Improving Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper, but its broad implicit triggers may make it activate more often than users expect.

Install this only if you are comfortable with a general workflow-helper skill being selected implicitly for some broad productivity or bug-fix requests. Consider narrowing or disabling implicit invocation if you only want it used when explicitly called by name.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence is broad and natural-language-like enough that unrelated user requests could accidentally activate the skill. In an agent ecosystem, overly permissive activation can cause the wrong workflow to run, leading to unintended actions, irrelevant guidance, or unsafe delegation under a misleading context.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The invocation guidance defines scope using vague need statements rather than concrete boundaries, making it difficult for routing logic or users to determine when this skill should apply. This increases the chance of over-triggering across many ordinary productivity requests, which is especially risky for a 'self-improving' and 'proactive' skill that may encourage broad, autonomous behavior.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad, generic, and overlap with normal productivity/help requests, which can cause the skill to activate outside its intended scope. In an agent ecosystem, this increases the chance of unneeded workflow interception, prompt shadowing, or accidental execution of a self-improving/proactive behavior pattern in unrelated conversations.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes extremely generic terms like "self," "improving," "proactive," and "bug fix," which are common in unrelated conversations. This can cause unintended invocation of the skill in contexts where it was not requested, potentially steering agent behavior, overriding more appropriate skills, or causing unsafe workflow automation to activate unexpectedly.

Vague Triggers

High
Confidence
94% confidence
Finding
The description says to use the skill whenever a user asks for broad categories like work-productivity, self, improving, or proactive, which are not sufficiently scoped. This ambiguity increases the chance that the skill will be selected for many unrelated requests, creating misrouting, unexpected behavior, and an expanded attack surface if the skill can influence workflows or generated artifacts.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list includes very broad common words such as 'self', 'improving', and 'proactive', which can match many unrelated user requests. This can cause accidental activation of the skill in contexts where it was not intended, leading to irrelevant guidance, workflow hijacking, or interference with more appropriate skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says to use the skill for broad categories of requests but does not clearly define boundaries or exclusions. Ambiguous triggering increases the chance that the skill is selected for loosely related tasks, which can misroute users and reduce reliability of agent behavior.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill can be implicitly invoked with a very broad description and trigger language, which increases the chance it will activate in contexts the user did not specifically intend. Because the skill is framed as proactive and self-improving, unintended invocation could cause it to influence workflows, suggestions, or actions more often than appropriate, expanding its operational reach without clear user consent.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger examples are extremely broad and include common words and generic help-seeking phrasing, which can cause the skill to activate for unrelated user requests. In an agent environment, this can misroute tasks, override more appropriate skills, and create unsafe or misleading automation behavior because the skill is invoked outside its intended scope.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.