Back to skill

Security audit

Work Productivity Tavily Web Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with overly broad activation wording, but it does not contain hidden execution, credential access, persistence, or data-moving behavior.

Installers should be aware that this skill may activate on generic web/search/API productivity requests. Prefer explicit invocation when using it, and consider narrowing the trigger phrases if publishing or maintaining the skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentence starts with broad everyday phrasing ('Help me') and embeds a long natural-language description rather than a narrowly scoped invocation. This can cause accidental activation when a user is merely discussing Tavily-style workflows, leading the agent to apply this skill out of context and potentially influence unrelated tasks.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger uses a broad request template ('I need a practical workflow for ...') that closely matches normal user conversation. In an agent ecosystem, this increases the chance of unintended skill routing, which can override user intent, introduce irrelevant instructions, or expose the agent to prompt-scope confusion.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are very broad and include common terms like 'work-productivity', 'web', 'search', 'api', and 'user', which can cause the skill to activate outside its intended scope. Overbroad activation increases the chance of unintended invocation, prompt collisions with other skills, and inappropriate handling of unrelated user requests, which is a real security and reliability concern in agent routing.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description is extremely broad and includes generic terms like 'work-productivity', 'web', and 'search', making it likely to activate for many unrelated requests. Over-broad routing can cause the wrong skill to be invoked, leading agents to apply irrelevant instructions or workflows in contexts the author did not intend.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords include multiple vague, high-frequency terms such as 'web', 'search', 'user', and 'api' that commonly appear in benign requests across many domains. This creates a strong risk of accidental skill selection, which can hijack task routing and degrade safety by inserting unrelated workflow guidance into other tasks.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences use ordinary phrasing that could match a wide variety of day-to-day requests, reinforcing overly permissive activation behavior. While examples are less dangerous than hard keywords, they still shape routing and increase the chance that the skill is selected outside its intended scope.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description and activation guidance are broad enough that ordinary user requests containing common terms like 'web', 'search', or 'via' could invoke this skill unintentionally. Over-broad triggering can cause routing confusion, irrelevant execution, and make it easier for adversarial prompts to steer the agent into this skill outside its intended scope.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes highly generic tokens such as 'web', 'search', 'api', and 'user' without scope restrictions, which materially increases accidental activation frequency. In an agent ecosystem, this can degrade prompt selection integrity and expose downstream tools or logic to requests that were never meant for this skill.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The example trigger phrases begin with common conversational patterns like 'Help me' and 'I need', which overlap with normal user dialogue and train overly permissive activation behavior. This raises the likelihood that routine assistance requests will match the skill even when the user did not intend Tavily workflow support.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The default prompt uses a very broad, natural-language invocation phrase ('Use $work-productivity-tavily-web-workflow-helper to help me...') that overlaps with ordinary user requests. In systems with implicit invocation enabled, this can cause the skill to activate unintentionally, expanding the attack surface for prompt injection, tool misuse, or unexpected workflow execution when unrelated user text happens to match the phrase.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is phrased as a broad natural-language request pattern rather than a narrowly scoped invocation condition. This can cause the skill to activate on unrelated user prompts containing common help-seeking language, leading to unintended routing, over-collection of context, or interference with more appropriate skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation description uses a generic request template that lacks discriminating criteria, so ordinary requests for practical workflows could match even when unrelated to this skill's domain. In an agent environment, this increases the chance of incorrect skill selection and unintended execution paths, which can degrade reliability and potentially expose adjacent tooling or data to unnecessary handling.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.