Back to skill

Security audit

Work Productivity Skillscan Security Workflow Helper

Security checks for vulnerabilities and agentic risk

Overview

The skill appears documentation-only and not malicious, but its automatic activation scope is much broader than its stated workflow purpose.

Review or narrow the activation metadata before installing in an environment that auto-loads skills. The content itself is low-risk documentation, but the current trigger set could cause the skill to appear in ordinary security, productivity, or planning conversations where the user did not intend to use it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad enough to match common words like 'security', 'every', 'must', or 'before', which can cause unintended activation in unrelated conversations. In an agent ecosystem, ambiguous routing can invoke this skill without clear user intent, leading to incorrect handling, confusion, or bypass of more appropriate workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad, natural-language prompts that overlap with ordinary user requests, which can cause the skill to activate in contexts unrelated to the author's intended scope. In an agent ecosystem, this increases the chance of unintended routing, capability overreach, and interference with other skills or workflows, especially because terms like 'help me' and 'I need a practical workflow' are common and not uniquely tied to this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description says to use the skill when a user asks for broad topics like "work-productivity," "security," or a "practical workflow," which are common across many unrelated requests. This creates a high risk of unintended activation, causing the wrong skill to be invoked in sensitive or irrelevant contexts and potentially steering users into an inappropriate workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The trigger keywords include highly ambiguous everyday terms such as "every," "must," "pass," and "before," which are likely to appear in ordinary conversation. Such generic triggers can cause accidental activation at scale, reducing reliability and potentially inserting this skill into unrelated security or productivity discussions.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger keyword list is extremely broad and includes common terms such as 'security', 'every', 'must', 'before', and 'bug fix', which are likely to appear in ordinary user prompts unrelated to this skill. This can cause unintended activation, routing confusion, and prompt-context injection into unrelated tasks, especially in environments that auto-select skills based on keyword matching.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger set includes extremely broad everyday terms such as "every," which can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance of unintended invocation, confusing routing behavior, and unsafe context capture because the skill may run outside its intended security-workflow scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file descriptions explicitly divide instructions and guides into English and Chinese variants, but the README does not state how the user's language preference is selected or whether the user can opt in. This can create a locale-handling policy issue if the skill defaults users into a language without an explicit choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The keyword list includes highly generic terms such as 'security', 'every', 'must', 'pass', 'before', and 'bug fix', which are common across many unrelated requests. This weak scoping can cause spurious activation and misclassification by orchestration layers, making the skill more dangerous in practice because its security-themed positioning may cause it to intercept or influence requests outside its proper context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example trigger sentences are malformed, overly broad, and do not show precise boundaries for activation. Poor trigger examples can mislead maintainers or routing systems into permissive matching behavior, increasing accidental invocation and making the skill's scope hard to control.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The invocation description says to use the skill when users mention broad categories like work-productivity, skillscan, security, gate, or every, or when they need general workflow/checklist/analysis support. These boundaries are too vague, making the skill eligible for many unrelated requests and increasing the chance of accidental activation or overshadowing more appropriate skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The default prompt contains broad, everyday activation language ('help me' plus generic work-productivity/security workflow terms) without meaningful scoping, which can cause the skill to be invoked in situations the user did not specifically intend. Because implicit invocation is enabled, this raises the chance of over-triggering, unwanted context capture, or the skill influencing unrelated conversations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation examples are vague and do not clearly separate intended security/workflow requests from ordinary productivity requests. In this skill context, that ambiguity is more dangerous because the skill is positioned as a helper for security and gating workflows, so accidental activation could misroute sensitive analysis tasks or apply the wrong workflow to unrelated user input.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.