Back to skill

Security audit

Work Productivity Skillscan Security Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but it does not request credentials, persistence, hidden execution, or unsafe authority.

Before installing, consider narrowing the trigger terms or disabling implicit invocation so this helper only activates when explicitly requested for SkillScan-style workflow support. The inspected skill is low risk operationally, but its broad activation language may make it appear in unrelated conversations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger sentences are extremely broad and include natural-language phrases that could plausibly appear in ordinary conversation, causing the skill to activate unintentionally. In an agentic environment, accidental invocation can route user requests into the wrong workflow, override more appropriate skills, or trigger security-relevant behavior when the user did not intend to use this skill.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The keyword list contains vague, high-frequency terms like "security," "gate," "every," "must," and "before," which are common in unrelated requests. This increases the chance of false matches and unintended skill selection, especially in systems that rely on keyword routing, potentially diverting sensitive or general-purpose tasks into this skill's workflow.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad, generic, and closely resemble normal user requests, which can cause the skill to activate in contexts far beyond its intended scope. In an agent ecosystem, this increases the chance of inappropriate routing, unintended invocation, and accidental handling of unrelated tasks under a security-themed workflow.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The keyword list includes highly generic terms like 'security', 'every', 'must', 'pass', and 'before', which are common across many unrelated conversations. This creates excessive overlap with ordinary prompts, making false activations likely and weakening routing integrity for security-sensitive workflows.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords include very common terms such as "security," "gate," "every," "must," "pass," and "before," which are likely to match many unrelated user requests. This can cause unintended skill activation and prompt-context injection into conversations where the skill is not relevant, reducing routing reliability and potentially interfering with safer or more appropriate skills.

Vague Triggers

High
Confidence
94% confidence
Finding
The manifest description says to use the skill when a user asks for broad categories like "work-productivity," "security," or "implementation support," which are ambiguous and applicable to many unrelated tasks. Overbroad invocation criteria can make the orchestrator select this skill inappropriately, causing scope confusion, unintended instruction injection, and degraded safety controls.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger section provides only broad keywords and example sentences, but lacks specificity, boundary conditions, and negative examples showing when the skill should not activate. This makes accidental activation more likely and increases the chance that irrelevant or conflicting instructions are injected into the session context.

Vague Triggers

High
Confidence
97% confidence
Finding
触发关键词包含“security”“gate”“every”“must”“pass”“before”“activate”等高度通用词,极易在无关对话中误触发该技能。误触发会把后续任务路由到与用户意图不符的工作流,导致错误的安全建议、上下文污染或覆盖更合适的技能选择。

Vague Triggers

Medium
Confidence
91% confidence
Finding
技能描述中的适用条件覆盖面很宽,如“需要实用流程、产物、检查清单、分析或实现支持时使用”,但缺少清晰边界,容易让调度器在大量普通生产力或安全相关请求中选中该技能。虽然这更像配置质量问题而非直接可利用漏洞,但会放大误路由和不必要激活的风险。

Vague Triggers

Medium
Confidence
94% confidence
Finding
示例触发句采用通用英文引导语如“Help me”“I need a practical workflow for”,且后续约束不足,可能使模型把普通求助句错误识别为该技能调用模式。示例通常会被模仿或用于少样本触发,因此宽泛示例会进一步扩大意外激活面。

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default_prompt includes very broad, common-language trigger terms and a generic invocation pattern, which can cause the skill to activate in unrelated conversations. This creates unintended routing and prompt-injection exposure because normal user requests about productivity, security, or workflows may invoke the skill without clear user intent.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling allow_implicit_invocation without strict activation constraints allows the platform to invoke the skill based on vague relevance matches rather than explicit user selection. In a security-oriented helper, this increases the chance of unintentional engagement, mis-scoped actions, and abuse through crafted prompts that steer execution into sensitive analysis or workflow steps the user did not clearly request.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger section uses broad generic keywords and phrases such as "security," "gate," "every," and "bug fix," which can cause the skill to activate in many unrelated contexts. Over-broad activation increases the chance of accidental invocation, context bleed, and inappropriate handling of user requests, especially in security-sensitive workflows where users may rely on the wrong skill or receive mismatched guidance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.