Back to skill

Security audit

Work Productivity Skillscan Security Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-only workflow helper with no executable code or credential handling, but its automatic activation rules are too broad.

Install only if you are comfortable with a broadly triggered workflow helper that may activate on generic security or workflow requests. Prefer invoking it explicitly by name, and consider narrowing or disabling implicit invocation if you maintain the package.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentence is extremely broad and includes generic phrasing like 'Help me' and 'I need a practical workflow,' which can cause accidental invocation during unrelated conversations. In an agent skill context, overly permissive activation increases the chance that the skill runs outside intended scope, potentially injecting workflow behavior or security guidance when the user did not explicitly request this specific skill.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The keyword list uses highly generic terms such as 'security,' 'every,' 'must,' 'pass,' and 'before,' which are common in normal user requests and create ambiguous activation boundaries. This makes accidental or unintended skill selection much more likely, which is especially risky for a workflow helper that may influence security-related decisions or gatekeeping behavior.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger phrases are broad generic terms such as 'security', 'gate', 'every', 'must', 'pass', 'before', 'activate', and 'bug fix', which can match many unrelated user requests and cause the skill to activate unexpectedly. In an agent environment, overbroad activation can route sensitive or irrelevant tasks through this skill, increasing the chance of prompt hijacking, unsafe workflow injection, or unintended interference with user intent.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords are extremely generic terms such as 'security', 'gate', 'every', 'must', and 'before', which are common in ordinary user requests. This can cause the skill to activate unintentionally in unrelated contexts, creating prompt-scope hijacking risk where this skill overrides or interferes with more appropriate skills or baseline behavior.

Vague Triggers

High
Confidence
96% confidence
Finding
The description says to use the skill when a user asks for broad categories like 'work-productivity' or 'security' or 'needs a practical workflow', which lacks meaningful boundaries. Such open-ended invocation criteria increase the chance of accidental routing and over-application of the skill to unrelated requests, reducing reliability and potentially displacing safer or more relevant instructions.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example triggers are vague restatements of the broad description and do not teach the router how to distinguish in-scope from out-of-scope requests. Poorly specified examples reinforce overbroad matching behavior and make accidental activation more likely, though the risk is somewhat lower than the trigger-list and description issues themselves.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords include very generic terms such as "security", "gate", "every", "must", "pass", and "before", which are common in many unrelated user requests. This can cause unintended auto-activation of the skill in contexts where it was not requested, increasing the chance of prompt injection, workflow hijacking, or irrelevant security guidance being inserted into unrelated tasks.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description says to use the skill when users ask for broad categories like work-productivity, skillscan, security, gate, or every, or whenever they need practical workflow or analysis support for the requirement. These boundaries are too vague, so the skill may activate in many unrelated situations and influence agent behavior outside its intended scope.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrases are ordinary help requests that resemble normal conversation and do not require an explicit tool-selection signal. This encourages accidental activation from everyday language, which can route user requests into this skill even when another skill or no skill would be more appropriate.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation without any visible trigger constraints or narrowing conditions, which can cause the agent to activate this skill for loosely related requests. Because the skill is framed broadly around productivity, workflows, security, checklists, and implementation help, over-triggering could route sensitive or irrelevant user queries into this skill unexpectedly, increasing the chance of unintended actions or disclosure.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The default prompt uses highly generic terms such as work-productivity, workflow, checklist, analysis, and implementation support, which overlap with common user language. In combination with implicit invocation, this broad phrasing makes accidental triggering more likely and can cause the skill to intercept ordinary requests that were not meant for it, creating prompt-routing and least-privilege issues.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger examples and keyword set are broad enough to match common words and generic requests, which can cause the skill to activate in contexts where the user did not intend it. In an agent ecosystem, unintended invocation can route tasks through the wrong workflow, producing irrelevant actions, confusing outputs, or unsafe processing of sensitive requests under an inappropriate skill.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The usage signals section defines ambiguous trigger scope without clear exclusions, making it hard for routing logic or users to distinguish when this skill should versus should not run. This increases the chance of accidental selection, cross-skill interference, and misclassification of ordinary productivity or security-related prompts into this workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.