Back to skill

Security audit

Work Productivity Skillscan Security Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is not destructive or data-stealing, but its very broad triggers and implicit auto-invocation could cause it to influence unrelated security or productivity tasks.

Review before installing if you rely on precise skill routing. The main risk is accidental activation on generic security, bug-fix, or workflow requests; narrowing triggers or disabling implicit invocation would make the skill easier to trust. I found no evidence of hidden execution, credential access, persistence, deletion, or exfiltration.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are extremely broad and include generic terms such as 'security', 'gate', 'every', 'must', 'pass', 'before', and 'activate', which can cause the skill to activate in many unrelated contexts. In an agent ecosystem, this creates routing confusion and accidental invocation risk, potentially overriding a more appropriate skill or causing users to receive unintended workflow guidance.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are extremely broad and include common terms like "security," "every," "must," "before," and "bug fix," which can cause the skill to activate for many unrelated user requests. In an agent ecosystem, this creates prompt-scope hijacking risk: the skill may be invoked unexpectedly, influencing workflows or analyses outside its intended domain and reducing user control over tool selection.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation guidance does not define firm boundaries for when the skill should and should not be used, and the examples are broad enough to match ordinary productivity or security requests. This ambiguity increases the chance of accidental activation, where the skill can override or interfere with more appropriate workflows, especially in security-sensitive contexts where precise tool routing matters.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords are extremely broad and include common terms like 'security', 'every', 'must', and 'before', which can cause the skill to activate for many unrelated requests. In an agent environment, this increases the chance of unintended routing or prompt-context injection, where the skill influences tasks it was not meant to handle.

Vague Triggers

High
Confidence
95% confidence
Finding
The description says to use the skill when a user asks for broad categories like 'work-productivity', 'security', or needs almost any 'workflow, artifact, checklist, analysis, or implementation support.' This ambiguous invocation condition can cause over-selection of the skill and unintended application to unrelated security or productivity tasks, expanding its authority beyond its intended scope.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example triggers are vague, repetitive, and closely mirror the description rather than demonstrating concrete, bounded use cases. Without specific examples and negative examples, a selector may match loosely similar user text and activate the skill inappropriately.

Vague Triggers

High
Confidence
96% confidence
Finding
触发关键词包含 `security`、`every`、`must`、`pass`、`before`、`activate` 等高度通用词,会让技能在大量无关场景中被误触发。对一个会影响工作流与安全决策的技能来说,误激活可能造成错误路由、覆盖更合适的技能,或把用户带入并不匹配的安全流程。

Vague Triggers

Medium
Confidence
87% confidence
Finding
技能描述中的适用条件覆盖面很广,如“work-productivity, skillscan, security, gate, every”以及“需要流程、产物、检查清单、分析或实现支持时使用”,边界不清晰。这样的描述会扩大匹配面,增加被错误选择或在低相关任务中介入的概率,降低系统行为可预测性。

Vague Triggers

Medium
Confidence
96% confidence
Finding
The skill enables implicit invocation while providing no narrowly scoped activation conditions, which increases the chance the agent will auto-select this skill for loosely related requests. Because the skill is framed around broad security and workflow assistance, unintended invocation could expose users to overreach, prompt confusion, or unsafe actions in contexts where the skill was not explicitly requested.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The default prompt uses highly generic trigger language such as 'help me' and broad keywords, which can cause the orchestration layer to match ordinary user requests that were not meant for this skill. In combination with implicit invocation, this makes accidental activation substantially more likely and can lead to incorrect tool routing or unnecessary exposure of the skill's behavior in unrelated conversations.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence includes extremely broad everyday terms such as "every" and "must pass before activate," which can cause the skill to activate on unrelated security or workflow requests. Overbroad activation increases the chance of unintended invocation, context hijacking, and misuse of the skill outside its intended scope.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The request pattern "I need a practical workflow for..." is too generic and can match a wide range of benign user requests unrelated to this skill's specialized purpose. In a skill-routing system, ambiguous trigger patterns can lead to accidental activation, incorrect tool selection, and increased exposure to prompt-crossing or unintended automation behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.