Back to skill

Security audit

Work Productivity Skillscan Security Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation metadata, but it does not request privileged access, run code, persist, or handle sensitive data.

Before installing, consider narrowing or disabling implicit invocation so the skill only activates for explicit SkillScan or ClawHub security-workflow requests. The inspected artifact does not show hidden code execution or sensitive access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentences and keywords are broad enough to match many ordinary user requests, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad activation can route unrelated tasks into this skill, creating incorrect security guidance, workflow confusion, or policy bypass opportunities if the skill is invoked when a more appropriate control should apply.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are generic natural-language requests that could match many ordinary user prompts unrelated to this specific skill. That creates overbroad activation risk, where the skill may be invoked unexpectedly and influence workflows outside its intended scope, especially in security-sensitive contexts.

Vague Triggers

High
Confidence
97% confidence
Finding
The keyword list includes very broad terms such as 'security', 'gate', 'every', 'must', 'pass', 'before', and 'activate', which are common across many unrelated conversations. Such ambiguous keywords can cause accidental routing or privilege-like influence over benign requests, increasing the chance that this skill intercepts tasks it was never meant to handle.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list is extremely broad, including generic words like "security," "every," "must," and "before," which are likely to appear in ordinary user requests. This can cause unintended activation and routing of unrelated conversations into this skill, increasing the chance of inappropriate instructions, noisy behavior, or security workflow overreach in contexts where the skill was not intended to run.

Vague Triggers

High
Confidence
89% confidence
Finding
The description says to use the skill when a user asks for very broad concepts like work-productivity, security, workflow, checklist, analysis, or implementation support, without clearly delimiting the skill's scope. That ambiguity makes the skill prone to overmatching and accidental invocation, which is especially risky because the skill can influence security-related guidance and workflow decisions in conversations that may not actually require it.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very common words such as "security", "every", "must", "pass", and "before", which can cause the skill to activate in many unrelated conversations. This creates prompt-routing risk: users may be unexpectedly steered into this skill, causing irrelevant behavior, policy interference, or accidental execution of the wrong workflow.

Vague Triggers

High
Confidence
92% confidence
Finding
The description says to use the skill when a user asks for broad categories like work-productivity, skillscan, security, gate, or every, or when they need almost any practical workflow or analysis support for the requirement. This ambiguity makes the activation boundary overly permissive, increasing the chance of unintended invocation and cross-context prompt capture.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default_prompt is broad, generic, and phrased in common help-seeking language, which increases the chance that the platform may invoke this skill in situations the user did not specifically intend. Because the skill is framed around security and workflow assistance, accidental activation could inject irrelevant or sensitive guidance into unrelated conversations and expand the skill’s effective scope beyond user expectations.

Vague Triggers

High
Confidence
97% confidence
Finding
Enabling allow_implicit_invocation without tight activation constraints makes the skill callable from loosely related user requests, raising the risk of unauthorized or surprising routing. In combination with the already broad prompt, this can cause over-invocation of a security-themed helper, which may expose internal workflow assumptions, alter task handling unexpectedly, or create opportunities for prompt-scope confusion.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger section includes broad, common words such as "security," "gate," and especially "every," "must," and "pass, before, activate," which can cause the skill to activate on unrelated user requests. Over-broad activation increases the chance of prompt interception or unintended routing, letting this skill influence conversations outside its intended scope and potentially override more appropriate safety or domain-specific handling.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.