Back to skill

Security audit

Work Productivity Skillscan Security Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

The skill is a non-executable workflow helper, but its automatic activation is under-scoped and could trigger on ordinary unrelated requests.

Review the activation behavior before installing. The skill appears safe as documentation, but it should ideally be invoked explicitly or with narrower trigger phrases so ordinary security, productivity, or bug-fix requests are not accidentally routed through it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases and keywords are broad enough that the skill may activate for unrelated requests containing generic terms like 'security', 'gate', 'every', 'must', or 'bug fix'. In an agent environment, overly permissive activation can cause the wrong skill to take control of a workflow, producing inappropriate actions or analyses and increasing the chance of unintended behavior.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger phrases are broad, generic, and likely to match ordinary user requests unrelated to this specific skill. That can cause the agent to invoke the skill unexpectedly, expanding its operational scope and creating unsafe or confusing behavior in security-sensitive workflows where the wrong helper may steer analysis or remediation.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The keyword list includes highly generic terms like 'security', 'every', 'must', 'pass', and 'before', which are common across many normal conversations. Ambiguous activation keywords increase the chance of accidental routing, causing this skill to intercept unrelated requests and potentially influence security decisions outside its intended context.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger list is overly broad and includes generic terms such as "security," "gate," "every," "must," and "before," which can cause the skill to activate in many unrelated contexts. This increases the chance of unintended routing, prompt interference, and unexpected disclosure of skill behavior in conversations that were not actually requesting this workflow.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says to use the skill when a user asks for broad categories like "work-productivity," "security," or needs a "practical workflow," which does not define clear activation boundaries. Ambiguous activation language can make orchestration systems select this skill too often, reducing predictability and potentially overriding more appropriate skills.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger phrases are generic templates that can match broad user language and they provide no exclusion conditions or disambiguation rules. In practice, such examples can train routing behavior toward over-selection, causing accidental invocation in unrelated conversations and increasing workflow confusion.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords are overly broad and include common terms such as "security", "gate", "every", "must", and "before", which can cause the skill to activate in many unrelated conversations. This increases the chance of unintended routing, context hijacking, or interference with other skills, especially in multi-skill environments where activation terms should be narrowly scoped.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description says the skill should be used when users mention broad categories or need general workflow/artifact support, but it does not define clear boundaries for when it should or should not activate. Ambiguous enablement criteria can lead to accidental invocation and inappropriate handling of user requests that belong to other skills or default assistant behavior.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The default prompt contains a very broad natural-language trigger phrase ('Use $work-productivity-skillscan-security-workflow-helper to help me...') tied to generic topics like productivity, security, workflows, and implementation help. Because implicit invocation is enabled, ordinary user requests can unintentionally match this phrasing and activate the skill when the user did not explicitly intend to call it, increasing the chance of prompt hijacking, scope creep, or unintended processing.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very broad generic terms such as "security," "gate," "every," and the phrase "must pass before activate," which are likely to appear in many unrelated user prompts. This can cause unintended invocation of the skill, leading to prompt-routing errors, unexpected exposure of the skill's instructions, and reduced reliability of security-sensitive workflows where precise tool selection matters.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.