Back to skill

Security audit

Work Productivity Skillscan Security Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with overbroad activation wording, but it does not request dangerous access, persistence, credential use, or hidden execution.

Installers should treat this as a low-risk workflow helper, but should narrow its triggers or disable implicit invocation if they want to avoid accidental activation on ordinary security or productivity conversations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger phrases are broad, generic, and overlap with ordinary user language such as 'help me' and 'I need a practical workflow,' which can cause the skill to activate in contexts far beyond its intended scope. In an agent ecosystem, this increases the risk of unintentional routing, inappropriate invocation on unrelated requests, and downstream execution of security-oriented workflows when the user did not explicitly ask for them.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation guidance is ambiguous because it mixes loose keywords ('security', 'gate', 'every', 'must', 'pass', 'before', 'activate') with example sentences that are not tightly scoped to a deliberate opt-in. This can make the skill activate on common productivity or security discussions, which is especially risky for a helper skill that may influence workflow decisions or gate behavior in broader agent operations.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are excessively broad and include generic terms like "security", "every", "must", "before", and "bug fix", which can cause the skill to activate for many unrelated user requests. In an agent ecosystem, this creates routing hijack risk: the skill may intercept normal conversations and steer users into this workflow without clear intent, increasing the chance of misapplied guidance or policy bypass through over-selection.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description says to use the skill when a user asks for very broad terms like "work-productivity," "security," or "needs a practical workflow," which are common in many unrelated requests. This can cause over-activation, routing users into this skill when it is not appropriate, increasing the chance of incorrect guidance, unintended influence on task selection, or masking more suitable specialized skills.

Vague Triggers

High
Confidence
99% confidence
Finding
The trigger keywords include extremely common words such as "security," "gate," "every," "must," "pass," and "before," which are likely to appear in ordinary conversation. In a skill-routing system, such ambiguous triggers can hijack unrelated requests, create unsafe or low-quality tool selection, and make the skill interfere broadly with normal agent behavior.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keyword list includes extremely broad everyday terms such as “security”, “every”, “must”, “pass”, and “before”, which can match many unrelated user requests and cause this skill to activate unintentionally. In an agent environment, over-broad activation can route sensitive or irrelevant tasks into the wrong workflow, increasing the chance of unsafe automation, confusing outputs, or bypass of more appropriate specialized skills.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description says it should be used when users ask for broad topics like work-productivity, skillscan, security, or practical workflow support, but it does not define clear inclusion and exclusion boundaries. This ambiguity makes dispatcher logic more likely to select the skill for loosely related requests, which can cause misrouting and weaken reliability or safety controls around task selection.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The example trigger sentences are highly generalized and effectively reinforce broad activation behavior instead of constraining it. Because examples often influence matching heuristics and future maintenance, these generic phrases can expand the practical trigger surface and increase accidental invocation frequency.

Vague Triggers

High
Confidence
95% confidence
Finding
The default_prompt is very broad and matches ordinary user language such as 'help me' plus generic productivity and security-related terms, which can cause the skill to activate when the user did not explicitly intend to invoke it. In practice this creates routing confusion, unintended tool/skill execution, and increases the chance that a sensitive or unrelated request is handled under this skill's instructions.

Vague Triggers

High
Confidence
93% confidence
Finding
Enabling allow_implicit_invocation without tightly scoped manifest constraints allows the platform to auto-select this skill based on vague semantic overlap rather than clear user intent. Because this skill targets broad workflow, analysis, checklist, and implementation support, accidental invocation is more dangerous: it can inappropriately steer conversations, expose users to unintended behavior, or interfere with safer/more specific skills.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger sentence is so broad that ordinary language could activate the skill unintentionally, causing inappropriate routing or invocation in unrelated conversations. In a security-oriented workflow, accidental activation is more dangerous because it may insert authoritative-sounding security guidance or workflow steps where they were not requested, reducing trust in routing and creating opportunities for prompt-surface abuse.

Vague Triggers

Medium
Confidence
88% confidence
Finding
This trigger example is ambiguous about when the skill should be invoked and does not clearly distinguish the intended use case from nearby but unrelated requests. Ambiguous invocation logic can lead to over-triggering, especially in agent ecosystems where skill selection is automated, and that can expose users to irrelevant or unsafe workflow behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.