Back to skill

Security audit

Work Productivity Skillscan Security Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but no hidden code, data access, persistence, or destructive behavior was found.

Installing this skill is reasonable if you want a general helper for SkillScan-style workflow and safety planning. Review its activation settings because it may be selected for ordinary security or productivity prompts; explicit invocation or narrower triggers would reduce accidental use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords and example sentences are so generic that this skill can activate for many unrelated prompts containing common words like "security," "gate," "every," or "bug fix." In an agent system, overly broad activation can cause the wrong skill to intercept tasks, override more appropriate workflows, or expose users to unintended instructions and outputs, especially for security-sensitive requests.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keywords and example invocations are broad enough to match ordinary security or productivity requests, which can cause this skill to activate unintentionally. In an agent ecosystem, over-broad routing is dangerous because it may override more appropriate skills, expand the skill's reach beyond user intent, and increase exposure to prompt collisions or unsafe workflow execution.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords are extremely broad and include common terms like "security," "gate," "every," "must," and "before," which can cause the skill to activate in many unrelated conversations. Overbroad activation increases the chance that this skill intercepts prompts outside its intended scope, leading to confused routing, unintended disclosure of user context to the skill, or unsafe reliance on a workflow that was not meant to apply.

Vague Triggers

High
Confidence
93% confidence
Finding
The manifest description says to use the skill when a user asks for broad categories like "work-productivity," "security," or "analysis," which are common across many unrelated tasks. A vague activation condition can make the platform invoke this skill too often, causing prompt misrouting and potentially exposing sensitive user requests or influencing security-related workflows where the skill is not the best fit.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger sentences are generic help requests and closely resemble ordinary user prompts, so they reinforce ambiguous activation behavior instead of clarifying when the skill should be used. This makes accidental invocation more likely and reduces the reliability of skill selection, especially in security-sensitive contexts where wrong-tool activation can distort analysis or recommendations.

Vague Triggers

High
Confidence
96% confidence
Finding
触发关键词包含 `security`、`every`、`must`、`pass`、`before` 等高频日常词,且缺少组合条件或上下文约束,容易在大量无关对话中误触发该技能。误触发会让本技能在不相关场景中介入并影响路由、输出内容或后续自动化流程;由于该技能又涉及“security/gate/workflow”类操作语境,错误介入会放大误导或越权决策风险。

Vague Triggers

Medium
Confidence
88% confidence
Finding
技能描述将适用范围表述为当用户提到 `work-productivity, skillscan, security, gate, every` 或“需要实用流程/分析支持”时使用,边界非常宽泛,未说明不应在哪些情境触发。这会导致调度器或操作者难以区分何时真正需要该技能,增加误调用和不恰当安全建议输出的概率。

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt uses a very broad natural-language invocation phrase ('Use $work-productivity-skillscan-security-workflow-helper to help me...') tied to generic terms like work, productivity, security, workflow, and help. This increases the chance of accidental or inappropriate activation during ordinary user requests, causing the skill to inject its behavior or instructions into conversations where the user did not explicitly intend to invoke it.

Vague Triggers

Medium
Confidence
96% confidence
Finding
Implicit invocation is enabled without any visible constraints, which means the platform may auto-select this skill for loosely related requests. Because the skill description and prompt are broad, this materially raises the risk of over-triggering, context leakage into unrelated tasks, and unintended execution paths that could affect user trust or produce unsafe guidance in the wrong context.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences and keyword list are overly broad and include common terms like 'security', 'gate', 'every', and 'bug fix', which can cause the skill to activate for many unrelated requests. In an agent environment, this creates routing confusion and can steer users into an unintended workflow, increasing the chance of incorrect automation, prompt hijacking exposure, or misuse of the skill outside its intended scope.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.