Back to skill

Security audit

Work Productivity Skillscan Security Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording but no hidden code, data access, persistence, or destructive behavior.

Installers should treat this as low-risk but noisy: it may trigger on ordinary security or bug-fix requests. Prefer explicit invocation or narrower trigger terms if you use it in a multi-skill environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentences are highly generic and include common phrases like 'help me' and 'I need a practical workflow,' which can cause the skill to activate in unrelated conversations. In an agent environment, overly broad activation increases the chance of unintended execution, routing sensitive requests into the wrong workflow, or allowing a skill to intercept prompts it was not meant to handle.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The keyword list contains extremely broad terms such as 'security,' 'every,' 'must,' 'pass,' 'before,' and 'bug fix,' which are likely to appear in many unrelated prompts. This creates prompt-routing ambiguity and raises the risk of accidental or excessive activation, especially in multi-skill systems where common words can hijack normal user requests.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords and example phrases are extremely broad, including generic terms like 'security', 'every', 'must', 'before', and 'bug fix'. This can cause the skill to activate on many unrelated user requests, creating routing hijacks or unintended invocation of this workflow in contexts where users did not ask for it.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description says to use this skill when a user asks for very broad terms like 'work-productivity', 'security', or 'implementation support', which overlap heavily with normal conversation. This can cause unintended activation or routing, making the agent apply this skill in contexts the user did not explicitly request, including sensitive security-related tasks where incorrect workflow injection could distort behavior.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes ambiguous everyday terms such as 'every', 'must', 'pass', 'before', and 'activate', which are likely to appear in many unrelated prompts. In agent systems that use keyword-based routing, this creates a high risk of spurious skill activation, leading to prompt-scope hijacking, misrouting, or unintended insertion of this skill's workflow into unrelated tasks.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example triggers are malformed, vague, and do not define precise invocation boundaries, so they fail to constrain when the skill should activate. This increases the chance that routing systems or maintainers will interpret broad fragments as valid triggers, compounding accidental activation risk created by the already broad description and keyword set.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords include very generic terms such as "security", "gate", "every", "must", "pass", and "before", which are likely to appear in many unrelated prompts. This can cause unintended skill activation and routing, increasing the chance that the wrong workflow is invoked and that user intent is misinterpreted or overshadowed by this skill.

Vague Triggers

High
Confidence
94% confidence
Finding
The description says the skill should be used when users ask for broad categories like work-productivity, skillscan, security, gate, or every, or when they need practical workflows or analysis, but it does not define meaningful boundaries. This ambiguity makes over-activation likely, especially because the skill claims a wide range of outputs, which can interfere with proper skill selection and degrade security-sensitive workflow routing.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger phrases are ordinary help requests that overlap with normal conversation, such as asking for a practical workflow or help fixing bugs and hardening. These examples train activation toward broad natural-language matches rather than a narrowly scoped request, making accidental invocation more likely.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt embeds a long, generic invocation phrase tied to broad terms like work-productivity and security workflow help, which can overlap with normal user language. Combined with allow_implicit_invocation: true, this increases the chance the skill is triggered unintentionally during ordinary conversation, causing unexpected behavior or unauthorized use of the skill's capabilities.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger set includes extremely broad, common terms such as "security," "gate," "every," and "activate," which can cause the skill to fire in many unrelated conversations. Unintended invocation can route users into the wrong workflow, override more appropriate skills, and create security-review bypass pressure if users assume the triggered skill is authoritative for unrelated tasks.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger description and example sentences do not define clear activation boundaries and are written broadly enough to match general requests for help, workflows, or security-related tasks. This ambiguity increases the chance of accidental activation and mis-scoping, especially because the skill claims broad support for analysis, checklists, implementation help, and adjacent workflows.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.