Back to skill

Security audit

Work Productivity Skillscan Security Workflow Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only workflow helper with some overly broad activation wording, but it does not install code, access credentials, persist, exfiltrate data, or request unusual authority.

Install only if you want a broad workflow helper for SkillScan-style security and reliability tasks. Be aware it may activate on generic security or bug-fix wording, so explicit invocation is safer if your environment allows controlling skill activation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords and example invocations are excessively broad for a security-related workflow helper, including generic terms like 'security', 'every', 'must', 'before', and 'bug fix'. This can cause unintended activation on ordinary conversations, routing users into the skill unexpectedly and increasing the chance of confused-deputy behavior, policy bypass opportunities, or over-collection of context from unrelated requests.

Vague Triggers

High
Confidence
97% confidence
Finding
The skill description is extremely broad and includes generic concepts like productivity, security, workflow, checklist, and implementation support. This can cause the skill to activate in many unrelated contexts, leading to unintended delegation, prompt-scope confusion, and increased exposure to adversarial or irrelevant instructions.

Vague Triggers

High
Confidence
99% confidence
Finding
The keyword trigger list contains highly generic words such as "security," "every," "must," "pass," and "before," which are likely to appear in ordinary conversations. This creates a high risk of accidental invocation or trigger hijacking, where unrelated prompts activate the skill and influence agent behavior unexpectedly.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords are extremely broad, including common words like "security", "every", "must", "pass", and "before", which can cause the skill to activate in many unrelated conversations. This creates an unsafe routing condition where the skill may intercept prompts outside its intended scope, increasing the chance of inappropriate guidance, prompt confusion, or privilege overreach in multi-skill environments.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger set includes very broad everyday terms such as 'security', 'gate', 'every', or 'activate', which are likely to appear in many unrelated prompts. This can cause unintended skill invocation, misroute user requests, and expose the skill's behavior in contexts where it was not explicitly requested, increasing prompt-routing and safety risk.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases and keywords are broad enough to match common terms like 'security', 'every', 'must', or 'before', which can cause accidental or unintended skill activation. In an agent environment, ambiguous activation increases the chance that this skill intercepts unrelated user requests, leading to workflow confusion, incorrect tool routing, or unintended execution paths.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
This file is presented as a Chinese README, but substantial user-facing content including the title, demand description, usage description, keywords, and trigger phrases is written in English. That effectively imposes a language choice on users of the zh-CN variant without opt-in or an explicit bilingual-language note.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences are malformed and overly permissive, so they fail to establish clear and safe boundaries for invocation. Poor examples can train users or routing systems to match on vague fragments, increasing false activations and making it easier for adversarial prompts to steer the agent into the skill unintentionally.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The description says the skill should be used when a user asks for broad themes like work-productivity, skillscan, security, or practical workflow help, but it does not clearly define boundaries for what is in or out of scope. Ambiguous activation criteria can lead orchestration systems or users to invoke the skill for loosely related requests, causing misrouting and potentially exposing users to irrelevant or unsafe workflow guidance.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases are generic and repetitive, focusing on broad requests like needing a practical workflow or help fixing bugs and hardening, without constraining the operational context. Because they lack negative examples or disambiguation, they reinforce overbroad matching behavior and make accidental or excessive activation more likely.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation while using a very broad description and default prompt that can match generic productivity, security, workflow, checklist, or implementation requests. This creates a prompt-triggering/scope-confusion risk where the skill may activate unintentionally in unrelated conversations, causing the agent to inject behavior or instructions the user did not explicitly request.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The usage signals define ambiguous activation scope without clear boundaries, so the skill may trigger on loosely related work-productivity or security requests. In an agent ecosystem, ambiguous routing can lead to inappropriate tool/skill selection, user confusion, and accidental execution of workflows that were not the best fit for the request.

Natural-Language Policy Violations

Low
Confidence
73% confidence
Finding
The file describes the skill instructions and guides as fixed English and Chinese variants, but does not state whether the user can choose their preferred language or locale. Under the language/locale policy, skills should not implicitly force a language arrangement without clear user choice or justification.

Static analysis

No suspicious patterns detected.