Back to skill

Security audit

Work Productivity Tavily Web Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad auto-invocation metadata, but no executable code, credential handling, persistence, or hidden behavior.

Installers should be aware that this skill may activate more often than intended for general web, search, or API requests. Review or narrow the trigger keywords and implicit invocation setting if precise routing matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and likely to activate on ordinary user requests unrelated to this specific skill. That increases the chance of unintended routing or invocation, which can cause the agent to apply the wrong workflow, mishandle user intent, or expose tool-enabled behavior in contexts where it was not expected.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The documented trigger phrases are very broad and closely resemble ordinary user requests, which can cause the skill to activate in unintended contexts. This increases the risk of misrouting user tasks, unexpected tool usage, or applying the workflow when the user did not explicitly request this skill, especially for common terms like 'web', 'search', 'api', and 'bug fix'.

Vague Triggers

High
Confidence
94% confidence
Finding
The skill description is extremely broad and includes common terms like "web," "search," and "via," which can cause the skill to activate in many unrelated contexts. This creates routing ambiguity and may result in the wrong skill being selected, causing unintended behavior, disclosure of irrelevant instructions, or reduced reliability of agent decision-making.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keyword list contains highly generic terms such as "web," "search," "via," "api," and "user," which are likely to appear in many unrelated prompts. In an agent ecosystem, this can lead to frequent accidental activation, misrouting, and interference with more appropriate skills, increasing the chance of incorrect outputs or unsafe workflow chaining.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases are written in broad everyday language and effectively encourage activation from loosely related requests without clarifying boundaries. This weakens selector precision and can cause the skill to capture prompts that should be handled by other skills or by the base agent directly.

Vague Triggers

High
Confidence
95% confidence
Finding
触发关键词包含极其常见的通用词,如“web”“search”“api”“user”“alternative”,会与大量普通对话重叠,导致技能被误触发。误触发后,代理可能在不相关任务中套用该技能流程,造成错误上下文注入、结果偏离用户意图,甚至掩盖更合适的安全约束。

Vague Triggers

Medium
Confidence
88% confidence
Finding
技能描述中的适用范围覆盖“work-productivity, tavily, web, search, via”以及“实用流程、产物、检查清单、分析或实现支持”等宽泛场景,但没有给出清晰边界。这样的模糊适用条件会让路由器或代理过度选择该技能,使其处理超出原始设计范围的请求,降低响应准确性并增加不当自动化的风险。

Vague Triggers

Medium
Confidence
91% confidence
Finding
示例触发句使用“Help me”“I need a practical workflow for”等高度通用表达,且几乎复述需求文案而非定义明确边界。这会鼓励基于模糊自然语言进行匹配,进一步放大误触发概率,使技能在无关任务中被调用。

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt is broadly phrased and overlaps with ordinary user requests about productivity, workflows, or help, which can cause the skill to activate outside a clearly intended context. In combination with an agent ecosystem that may support automatic routing, this increases the risk of unintended invocation, prompt-surface expansion, and accidental handling of tasks the user did not explicitly request through this skill.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without scoped conditions allows the platform to call this skill based on weak intent matching rather than explicit user consent or constrained routing rules. That makes accidental or excessive activation more likely, which can expose users to unintended behavior, broaden the attack surface for prompt injection through retrieved content, and interfere with principle-of-least-privilege skill selection.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases begin with very common language such as 'Help me' and 'I need', which can cause the skill to activate for broad, unrelated user requests. In an agent routing system, this increases the chance of misrouting prompts into this skill, leading to unintended web/search workflow behavior, confusion, or unsafe delegation when the user did not explicitly request this capability.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.