Back to skill

Security audit

Work Productivity Self Improving Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation language, but no artifact evidence of hidden code execution, data access, persistence, or destructive behavior.

Install only if you want a general workflow helper for self-improving or proactive agent work. Be aware that its trigger terms are broad and implicit invocation is enabled, so it may appear for ordinary productivity or bug-fix requests; review any suggested workflow, code, or skill changes before applying them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger examples are broad enough to match ordinary user requests about help, workflows, or practical support, which can cause the skill to activate in contexts the user did not clearly intend. In a self-improving/proactive workflow skill, accidental invocation is more dangerous because the skill may steer planning, process changes, or adjacent skill creation without explicit opt-in.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The README describes workflow assistance but does not warn that the skill may proactively modify workflows, harden setups, or create adjacent skills, all of which can affect reliability and safety. Without prominent disclosure, users may authorize the skill under incomplete assumptions and be surprised by consequential changes to their processes or derived artifacts.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad and map to common terms like 'help me', 'practical workflow', and generic concepts such as 'self', 'improving', or 'proactive'. This can cause the skill to activate for unrelated user requests, unexpectedly inserting its workflow into normal conversations and increasing the chance of prompt-routing mistakes or misuse.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes extremely generic terms such as 'self', 'improving', and 'proactive', which are common in benign everyday prompts. This can cause accidental over-activation of the skill in unrelated contexts, leading to prompt-routing mistakes, unexpected behavior, and increased exposure to whatever instructions or assumptions the skill contains.

Vague Triggers

High
Confidence
92% confidence
Finding
The invocation description is broad enough to match vague user requests like needing 'practical workflow, artifact, checklist, analysis, or implementation support,' combined with generic terms. This weak scoping increases the chance that the skill is invoked outside its intended domain, which can override better-matched skills or inject irrelevant workflow behavior into normal conversations.

Vague Triggers

High
Confidence
96% confidence
Finding
触发关键词包含 `self`、`improving`、`proactive` 等非常宽泛的普通词,会让该技能在大量无关上下文中被误触发。对一个会生成流程、分析、代码修改或决策支持的技能来说,误调用会扩大其作用面,增加提示注入、越权干预用户任务或干扰正确技能路由的风险。

Vague Triggers

Medium
Confidence
90% confidence
Finding
技能描述把适用范围定义为 `work-productivity`、`self`、`improving`、`proactive` 以及几乎任何“实用流程、产物、检查清单、分析或实现支持”请求,边界非常模糊。这会导致选择器将大量普通工作流请求错误归入该技能,使其在不必要的场景中介入,降低安全路由精度。

Natural-Language Policy Violations

Medium
Confidence
72% confidence
Finding
文档整体强制为中文 locale,未说明是否可按用户语言切换,也未提供多语言选择。虽然这不是直接代码执行类漏洞,但它会造成误解、错误配置或审查遗漏,特别是在安全相关工作流中,语言不匹配会降低用户对限制、假设和风险说明的正确理解。

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt contains a very broad natural-language trigger phrase covering generic terms like work-productivity, self, improving, and proactive. In combination with agent routing, this can cause accidental or overly frequent invocation during ordinary user conversations, expanding the skill’s influence beyond clearly intended cases and increasing prompt-injection and misrouting risk.

Vague Triggers

Medium
Confidence
94% confidence
Finding
Enabling implicit invocation without tightly scoped activation criteria allows the skill to be invoked automatically based on ambiguous user language rather than explicit selection. This increases the chance of unintended execution, context hijacking by adjacent prompts, and unsafe delegation in situations where the user did not knowingly request this skill.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentence begins with a very broad everyday phrase ('Help me ... practical help') that can match many unrelated user requests and cause the skill to activate outside its intended scope. In an agent ecosystem, over-broad activation increases the chance of unintended delegation, context confusion, and unsafe execution of a workflow the user did not explicitly request.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The phrase 'I need a practical workflow for ... practical help' is vague and lacks clear activation boundaries, so normal planning or productivity requests could be incorrectly routed to this skill. Because the skill is framed as proactive and self-improving, accidental invocation may amplify downstream actions or recommendations beyond what the user intended.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.