Back to skill

Security audit

Work Productivity Skillscan Security Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This skill does not contain executable or credential-stealing behavior, but its broad triggers and implicit invocation make accidental activation likely enough to require review.

Review the activation behavior before installing. The skill appears documentation-only, but it should ideally be invoked only by explicit name or narrow SkillScan workflow phrases so it does not intercept unrelated security, productivity, or coding requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger examples are phrased as broad, natural-language requests that are likely to appear in unrelated conversations, increasing the chance the skill activates when the user did not explicitly intend to invoke it. In an agent ecosystem, unintended activation can route tasks through the wrong workflow, causing incorrect security analysis, unnecessary privilege use, or disruption of higher-priority instructions.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The keyword list includes generic terms like 'security,' 'gate,' 'every,' 'must,' 'pass,' 'before,' and 'activate,' which are common in many benign prompts and therefore create a high risk of accidental matching. Over-broad activation logic is dangerous because it can cause this skill to intercept unrelated requests, leading to unintended workflow execution and weakening the predictability and safety boundaries of the agent system.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad, generic, and include common terms like "security", "every", "must", and "bug fix", which can cause the skill to activate in unrelated contexts. In an agent ecosystem, unintended activation can route user requests into the wrong workflow, creating security-review bypasses, confusing task delegation, or unsafe automation when users did not explicitly request this skill.

Vague Triggers

High
Confidence
98% confidence
Finding
The skill description and activation guidance are broad enough that ordinary user requests containing generic workflow or security terms could invoke this skill unintentionally. Over-broad activation increases the chance of inappropriate routing, causing the agent to apply the wrong instructions or context to unrelated tasks, which is especially risky for security-sensitive workflows.

Vague Triggers

High
Confidence
99% confidence
Finding
The keyword list includes extremely common words like "security," "gate," "every," "must," and "before," which are likely to appear in many unrelated prompts. This creates a high risk of accidental activation and prompt hijacking of normal conversations, potentially overriding more appropriate skills or injecting irrelevant workflow behavior into sensitive tasks.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger sentences reinforce activation on vague, reusable phrasing rather than clearly scoped requests, training users and downstream systems to invoke the skill in overly broad contexts. This broadens the attack surface for misrouting and makes accidental activation more likely across many unrelated productivity or security requests.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very generic terms such as "security", "every", "must", "pass", and "before", which are common in unrelated user prompts. This can cause the skill to activate unintentionally and override or interfere with more appropriate skills, creating prompt-routing risk and potentially exposing users to irrelevant or unsafe workflow behavior in security-sensitive contexts.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says to use the skill when a user asks for broad categories like work-productivity, skillscan, security, gate, or every, or whenever they need practical workflow or analysis support for the requirement. This is an ambiguous activation boundary that can capture a wide range of unrelated requests, increasing the chance of unintended invocation and misrouting in multi-skill environments.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt invokes the skill through a very broad phrase tied to common terms like work-productivity, security, workflow, and implementation support, without clear boundaries on when the skill should activate. Combined with allow_implicit_invocation: true, this increases the chance of unintended or overly aggressive routing, which can expose users to irrelevant or unsafe automation paths and make prompt-trigger abuse easier.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger sentences are phrased as broad, everyday requests and directly embed generic language like 'help me' and 'I need a practical workflow,' which can cause the skill to activate on unrelated conversations. In an agent ecosystem, overly permissive activation expands the skill's execution surface and may route sensitive or security-relevant user requests into this skill unintentionally, creating misfires, confused-deputy behavior, or unsafe task handling.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The keyword list includes extremely broad terms such as 'security,' 'gate,' 'every,' 'must,' and 'bug fix' without contextual qualifiers, making accidental activation likely across many unrelated tasks. This weak scoping is dangerous because it can hijack routing decisions, causing the skill to engage outside its intended domain and potentially interfere with safer or more appropriate skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.