Back to skill

Security audit

Work Productivity Skillscan Security Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with no code execution or data access, though its broad auto-invocation terms may make it appear in unrelated requests.

Before installing, be aware that the skill may be selected for generic security or workflow requests because of broad trigger wording. Prefer explicit invocation by skill name, and maintainers should narrow the trigger terms if they want predictable routing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger examples include very generic phrasing around common productivity and security terms, which can cause the skill to activate in unrelated conversations. In an agent ecosystem, overly broad activation increases the chance of unintended instruction injection, workflow hijacking, or the skill taking over tasks outside its intended scope.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The invocation guidance does not define strict boundaries for when the skill should or should not run, and the listed keywords are broad enough to match many normal requests. This ambiguity can lead to accidental activation and unsafe context switching, especially in multi-skill agents where the wrong skill may process sensitive or security-relevant tasks.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests such as 'security', 'gate', 'must', 'before', or 'bug fix', which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad activation is dangerous because it can silently intercept unrelated tasks, override more appropriate skills, or steer users into this workflow without clear consent.

Vague Triggers

High
Confidence
94% confidence
Finding
The skill description is broad enough to match many ordinary security- or workflow-related requests, which can cause unintended activation outside the author's intended scope. Over-broad invocation increases the chance that the wrong skill handles a request, leading to unsafe guidance, context confusion, or bypass of more appropriate specialized skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keyword list includes generic words such as 'security', 'gate', 'every', 'must', 'pass', and 'before', which are common in normal conversation and likely to cause accidental invocation. This creates routing ambiguity and may let the skill intercept unrelated prompts, reducing reliability and potentially introducing unsafe or irrelevant workflow outputs.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrases are malformed, overly vague, and effectively restate broad marketing language rather than showing precise invocation conditions. Poor examples encourage misconfiguration and make it harder for maintainers or routing systems to understand when the skill should and should not activate.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list includes very common words such as "security", "every", "must", "pass", "before", and "activate", which are likely to appear in many unrelated user prompts. This can cause the skill to activate unintentionally, leading to misrouting, unexpected behavior, and possible interference with other skills or workflows.

Vague Triggers

High
Confidence
92% confidence
Finding
The description says to use the skill whenever users ask for broad categories like work-productivity, skillscan, security, gate, or practical workflow support, which creates ambiguous activation boundaries. In a multi-skill environment, this increases the chance of over-triggering and routing user requests to this skill when another tool would be more appropriate.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables implicit invocation while providing a broad, generic description tied to common terms like work-productivity, security, workflow, and checklist-style help. This can cause the agent to auto-select the skill in situations the user did not clearly intend, expanding the skill’s influence over unrelated prompts and increasing the chance of unsafe or misleading actions in security-sensitive contexts.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger content includes broad, ordinary words such as 'security', 'gate', and 'every' in a way that can match many unrelated user requests. This can cause unintended skill activation, routing sensitive or irrelevant conversations into this workflow and undermining user intent boundaries.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger section lacks clear boundaries and contains malformed example sentences that effectively broaden matching instead of constraining it. In an agent ecosystem, ambiguous routing rules can be exploited indirectly by causing over-invocation, confused delegation, or accidental use in contexts the user did not request.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.