Back to skill

Security audit

Work Productivity Skillscan Security Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This documentation-only skill is not destructive, but it is configured to auto-activate on overly broad terms that could affect unrelated conversations.

Install only if you are comfortable with a broad workflow helper potentially being invoked for generic security or productivity requests. The safer version would disable implicit invocation or require an explicit skill name or narrowly scoped SkillScan workflow phrase.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentences and keywords are broad enough to match common security and productivity requests that may not actually intend to invoke this specific skill. That increases the chance of unintended activation, causing the agent to route user requests into this workflow unexpectedly and potentially influencing security-sensitive tasks without explicit user intent.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests, which can cause the skill to activate outside its intended scope. In an agent environment, this creates unsafe routing and prompt-surface expansion, where a security-oriented workflow may intercept unrelated tasks and influence behavior unexpectedly.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The keyword-based activation list is ambiguous and includes common words such as 'every', 'must', 'pass', and 'before', which are likely to appear in many benign prompts. This increases the chance of accidental activation, causing misrouting, unnecessary privilege exposure to the skill instructions, and unreliable agent behavior.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger list includes generic words like "security," "every," "must," "pass," and "before," which are common in many unrelated prompts. This can cause unintended skill activation and context hijacking, where the wrong skill takes over a conversation and influences outputs outside its intended scope.

Vague Triggers

High
Confidence
95% confidence
Finding
The description says to use the skill when a user asks for broad categories like work-productivity, security, or practical workflow support, which creates an ambiguous and expansive activation condition. In an agent system, overly broad routing criteria can misfire frequently, causing this skill to activate for unrelated requests and potentially override more appropriate or safer workflows.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger sentences are incomplete and malformed, and they do not establish a clear invocation boundary between natural language discussion and intentional skill activation. This increases the chance that simple mention of related phrases will accidentally trigger the skill, reducing routing reliability and making prompt-control behavior easier to manipulate.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keyword list includes very broad everyday terms such as "security", "every", "must", "pass", and "before", which can cause the skill to activate in many unrelated conversations. Over-broad auto-activation is dangerous because it can hijack routing, inject irrelevant workflow behavior into security-sensitive tasks, and reduce user control over which skill is invoked.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description says to use the skill when a user asks for broad categories like work-productivity, skillscan, security, gate, or every, or whenever they need a practical workflow or checklist. This ambiguous activation scope lacks clear boundaries and can cause unintended invocation for many benign requests, especially because several listed terms are generic across normal assistant usage.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The skill enables allow_implicit_invocation without defining narrow trigger conditions, which creates a realistic risk of the skill being auto-invoked for loosely related user requests. Because this skill is framed around broad workflow and security-help tasks, unintended invocation could insert unrequested guidance or cause the agent to route sensitive or general-purpose requests into this skill unexpectedly.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The default prompt uses very broad, everyday phrasing such as helping with practical workflow, checklist, analysis, implementation support, fixing bugs, and hardening, which overlaps with many normal user requests. In combination with implicit invocation, this increases the chance of overbroad routing, accidental activation, and unintended influence over unrelated conversations.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger section includes broad, everyday terms and generic phrases like "security," "gate," "every," and "Help me," which can match many unrelated user requests and cause accidental skill activation. In an agent environment, overbroad invocation increases the chance that this skill intercepts tasks outside its intended scope, leading to incorrect workflow execution, user confusion, or unsafe delegation in security-sensitive contexts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.