Back to skill

Security audit

Work Productivity Tavily Web Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only workflow helper with overbroad activation wording but no hidden code, credential access, persistence, or destructive behavior.

Before installing, be aware that this skill may be selected for broad web/search/productivity prompts. It appears safe as a documentation workflow helper, but users or maintainers should narrow its triggers if precise skill routing matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad, generic, and likely to match ordinary user requests unrelated to this specific skill, which can cause the wrong skill to activate and steer users into unintended workflows. In an agent ecosystem, overbroad activation increases the attack surface for prompt-routing mistakes, accidental capability invocation, and user confusion, even though the README itself does not contain direct code execution behavior.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad and partially match ordinary help-seeking language, which can cause the skill to activate in contexts the user did not explicitly intend. In an agent ecosystem, this increases the chance of incorrect routing, unnecessary invocation of web-search workflows, and accidental handling of unrelated requests, which can degrade safety and reliability.

Vague Triggers

High
Confidence
95% confidence
Finding
The manifest description uses very broad activation terms like work-productivity, web, search, and implementation support, which can cause the skill to be invoked for many unrelated user requests. Over-broad routing increases the chance this skill intercepts tasks outside its intended scope, leading to unintended behavior, prompt-surface expansion, and unsafe delegation in agent workflows.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keyword list includes generic words such as web, search, api, user, and alternative, which are common across many benign prompts. In an automated skill-selection system, these vague triggers can cause excessive or accidental activation, exposing users to irrelevant instructions and increasing the attack surface for prompt-routing abuse.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger sentences are broad natural-language prompts that mirror common user requests without meaningful scope constraints. These examples may train or bias routing systems toward activating the skill for loosely related requests, compounding the over-broad matching problem created by the manifest and keyword list.

Vague Triggers

High
Confidence
97% confidence
Finding
触发关键词包含非常常见且语义宽泛的词,如“web”“search”“user”“api”“alternative”,会让技能在大量无关场景中被错误激活。误触发会扩大该技能对对话流的影响范围,造成路由混乱、错误建议注入,甚至让本不应参与的技能接触更多用户上下文。

Vague Triggers

High
Confidence
95% confidence
Finding
技能描述将适用范围定义为用户提到 work-productivity、tavily、web、search、via 或需要“实用流程、产物、检查清单、分析或实现支持”时使用,这一表述过宽,几乎可覆盖大量普通生产力或搜索相关请求。边界不清会导致技能被过度调用,降低系统对正确技能的选择精度,并可能把不必要的上下文暴露给该技能。

Vague Triggers

Medium
Confidence
88% confidence
Finding
The default prompt contains a very broad invocation phrase tied to generic terms like work-productivity, tavily, web, search, workflow, artifact, checklist, analysis, and implementation support. This can cause the skill to activate in contexts beyond the user's intent, increasing the chance of prompt hijacking, unintended tool usage, or accidental exposure of this skill's behavior in unrelated conversations.

Vague Triggers

Medium
Confidence
93% confidence
Finding
Enabling implicit invocation without tight activation constraints makes the skill eligible to run automatically on ambiguous requests. In a helper skill focused on web/search workflows, this broad auto-activation increases the risk of unintended invocation, context bleed from unrelated tasks, and unsafe chaining into web-oriented operations the user did not explicitly request.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentences include broad, natural-language phrasing such as 'Help me' and 'I need a practical workflow', which can match many unrelated user requests and cause accidental skill activation. In an agent environment, overbroad routing increases the chance that this skill is invoked outside its intended Tavily/web-workflow context, leading to irrelevant actions, user confusion, or unsafe delegation to a capability the user did not explicitly request.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.