Back to skill

Security audit

Work Productivity Skill Vetter Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad auto-activation terms but no hidden execution, data access, or persistence.

Installers should be aware that this skill may activate too often because of generic keywords and implicit invocation. It is otherwise low-risk: it provides workflow guidance and does not include executable code, credential handling, persistence, or data exfiltration behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are generic and include broad terms like 'security', 'github', and 'bug fix', which can cause the skill to activate in situations beyond its intended scope. In an agent environment, overbroad activation can route unrelated or sensitive tasks into this workflow, increasing the chance of incorrect handling, unintended prompt influence, or user confusion.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough to activate on generic terms like 'security', 'github', or 'bug fix', which can cause this skill to run in unintended contexts. In an agent ecosystem, overbroad activation can misroute sensitive or unrelated requests into this workflow, increasing the chance of incorrect handling, prompt injection exposure, or user confusion.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description and activation guidance are overly broad, including generic security- and productivity-related phrasing that can match many unrelated requests. This creates a real risk of unintended invocation, causing the wrong skill to steer conversations or influence security-sensitive workflows when the user did not explicitly ask for it.

Vague Triggers

High
Confidence
99% confidence
Finding
The trigger keyword list includes very common terms such as 'security', 'first', 'before', 'github', and 'bug fix', which are too vague for reliable routing. In practice, this can cause accidental activation across a large number of benign conversations, increasing the chance of incorrect guidance, prompt interference, or unwanted priority over more appropriate skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example triggers only show positive matches and do not define non-matches or boundary conditions, making activation behavior ambiguous. This ambiguity increases the likelihood that integrators or routing systems will apply the skill too broadly, especially given the already-generic keywords and security-adjacent context.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are overly broad, including generic terms like 'security', 'first', 'before', and 'github', which can cause the skill to activate for many unrelated user requests. In an agent environment, this can misroute tasks, override more appropriate skills, and produce irrelevant or confusing outputs that degrade reliability and may interfere with security-sensitive workflows.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description defines activation conditions too broadly and ambiguously, covering a wide range of users and requests for workflows, artifacts, checklists, analysis, or implementation support. This lack of boundary clarity increases the chance of unintended invocation, causing the agent to apply this skill outside its intended scope and potentially disrupt task routing or introduce unsuitable guidance.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The default prompt is framed with broad, generic trigger terms such as work-productivity, security, checklist, analysis, and implementation support, which can cause the skill to activate in many unrelated conversations. Because the skill is security- and workflow-oriented, unintended invocation could insert untrusted guidance into sensitive tasks or steer users into using this skill when they did not explicitly request it.

Vague Triggers

Medium
Confidence
97% confidence
Finding
Enabling implicit invocation without tight scoping allows the platform to auto-route ordinary user requests to this skill based on ambiguous language. In a security-adjacent helper skill, this increases the chance of prompt-surface expansion, accidental tool use, or misleading assistance being injected into conversations that were not intended to involve this workflow.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences and keywords include broad, common terms such as "security," "first," "github," and generic help phrasing, which can cause the skill to activate for many unrelated requests. In an agent ecosystem, over-broad activation can route sensitive or unintended tasks into this skill, increasing the chance of confused-deputy behavior, incorrect automation, or interference with more appropriate skills.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.