Back to skill

Security audit

Work Productivity Skillscan Security Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a text-only workflow helper with overly broad auto-invocation wording, but it contains no code, hidden data handling, persistence, or credential access.

Installers should be aware that this skill may activate for generic security or workflow language. Prefer explicit invocation or narrower trigger metadata if precise routing matters; there is no evidence here of malicious behavior, data exfiltration, destructive commands, or hidden persistence.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad, generic help-seeking language that could cause the skill to activate for unrelated user requests. In an agent ecosystem, this can misroute tasks, unexpectedly invoke the skill, and create unsafe or confusing workflow substitutions, especially because the skill is security-themed and may be applied outside its intended scope.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords and example phrases are broad enough to match ordinary requests like 'security', 'every', 'must', or 'bug fix', which can cause the skill to activate unexpectedly outside its intended context. In an agent ecosystem, this creates prompt-routing confusion and can steer unrelated user tasks into this skill's workflow, increasing the chance of inappropriate behavior or unsafe handling of sensitive requests.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description is broad enough to match many ordinary requests such as 'security', 'workflow', 'checklist', or 'analysis', which can cause unintended activation outside its intended scope. Over-broad activation increases the chance that this skill intercepts unrelated tasks, influencing agent behavior or bypassing more appropriate, narrower skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keywords include generic everyday words like 'every', 'must', 'pass', 'before', and 'activate' with no contextual guardrails. Such terms are likely to appear in many unrelated prompts, creating accidental invocation and widening the skill's control surface in ways that can misroute agent workflows.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The example trigger sentences are malformed and do not establish clear invocation boundaries, which makes matching behavior ambiguous. Ambiguous examples can lead implementers to create permissive trigger logic that activates on partial or unrelated text, increasing accidental or adversarial routing opportunities.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list is excessively broad and includes common words like "security", "every", "must", "pass", and "before", which are likely to appear in ordinary conversations unrelated to this skill. That creates accidental activation and routing risk, causing the agent to invoke this skill outside its intended scope and potentially override more appropriate safety or task-specific workflows.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says to use the skill when users ask for broad themes like work-productivity, skillscan, security, or practical workflow support, but it does not clearly bound when the skill should and should not activate. This ambiguity increases misrouting risk, especially because the skill appears security-related and may be selected for unrelated requests that merely mention security or workflow terms.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The skill enables allow_implicit_invocation without any visible activation constraints, which means it can be invoked from broad user phrasing rather than explicit user intent. In a security-oriented helper, this increases the chance of unsolicited routing, prompt-surface expansion, and accidental application of the skill in unrelated conversations, which can mis-handle sensitive workflow or security guidance.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The default prompt uses very broad trigger terms such as 'work-productivity,' 'security,' 'workflow,' 'checklist,' 'analysis,' and 'implementation support,' which overlap heavily with common user requests. When combined with implicit invocation, this can cause overmatching and unintended activation, exposing users to irrelevant or overly powerful behavior and making routing abuse easier.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger guidance includes extremely broad everyday terms such as "every" and "security" in a way that can cause accidental invocation during unrelated conversations. In an agent environment, over-broad activation can route sensitive or irrelevant tasks into this skill unexpectedly, increasing the chance of context leakage, incorrect tool use, or workflow interference.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation section lacks scoped conditions and instead relies on broad language that can match many unrelated user requests. This makes the skill easier to invoke unintentionally, which is dangerous because the skill is positioned as a workflow/helper and may influence outputs even when the user's request does not actually call for it.

VirusTotal

39/39 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.