Back to skill

Security audit

Work Productivity Skillscan Security Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with no executable code, but its activation keywords are too broad and could make it appear in unrelated requests.

Before installing, consider narrowing or disabling implicit invocation so this helper only activates for explicit SkillScan or skill-security workflow requests. As written, it is low-risk but may be noisy in unrelated security or productivity conversations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

High
Confidence
94% confidence
Finding
The skill advertises very broad keywords and trigger phrases such as 'security', 'every', 'must', and 'before', which can cause the agent to invoke this skill in many unrelated contexts. In a security-oriented workflow helper, overbroad activation increases the chance of unintended interception of user requests, misrouting, and unsafe application of generic security guidance where it does not belong.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger keywords and sample activation phrases are broad enough to match common security- and productivity-related requests, which increases the chance the skill activates when the user did not specifically intend to invoke it. In an agent ecosystem, unintended activation can route user tasks through the wrong workflow, causing incorrect actions, confusing outputs, or bypass of more appropriate safeguards.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description says to use the skill when a user asks for broad terms like "work-productivity," "security," "gate," or "every," which are common across many unrelated prompts. This creates a realistic risk of unintended invocation, causing the wrong workflow to steer conversations, override more appropriate skills, or inject irrelevant security/process behavior into benign tasks.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes ambiguous everyday words such as "every," "must," "pass," and "before," which are likely to appear in ordinary requests unrelated to this skill. Such broad triggers can cause frequent false activations, creating prompt-routing instability and making downstream behavior less predictable or controllable.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The example trigger sentences are malformed, repetitive, and too vague to establish clear activation boundaries. Poor examples increase the chance that integrators or routing systems will infer an overly permissive match policy, which compounds the risk of accidental activation from the already-broad trigger language.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list includes very common terms such as "security", "every", "must", "pass", and "before", which can cause the skill to activate in many unrelated conversations. Over-broad activation can unexpectedly route users into this skill, leading to incorrect assistance, prompt-context pollution, or interference with more appropriate skills in security-sensitive workflows.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The description says to use the skill for broad topics like work-productivity, skillscan, security, gate, and every, but does not clearly define exclusion conditions or what distinguishes this skill from adjacent ones. This ambiguity increases the chance of accidental invocation and misrouting, especially because the skill operates in reliability and security-related contexts where precision matters.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill enables implicit invocation while using very broad trigger language such as generic work-productivity and workflow-help terms. This can cause the agent platform to auto-select the skill in unrelated conversations, expanding the chance that sensitive user data or security-relevant tasks are routed into this skill without clear user intent or review.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger section includes highly generic terms and phrasing such as 'security', 'gate', 'every', and 'must pass before activate', which can cause the skill to match routine user requests that were not intended to invoke this specific workflow. In an agent environment, overly broad activation criteria can misroute tasks, create prompt confusion, and increase the chance that this skill runs in inappropriate contexts where it may shape security-sensitive guidance incorrectly.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.