Back to skill

Security audit

Work Productivity Tavily Web Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with no hidden execution, credential use, persistence, or destructive behavior, though its activation wording is overly broad.

Installers should be aware that this skill may activate for generic web/search/API requests because of broad trigger wording. It appears safe as a documentation/workflow helper, but authors should narrow the triggers to explicit Tavily or web-search workflow tasks to reduce accidental use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentences are broad, generic, and likely to match ordinary user requests unrelated to this specific skill. In an agent-routing system, this can cause unintended invocation of the skill, leading to prompt hijacking opportunities, incorrect tool selection, or accidental exposure of web/search-enabled workflows in contexts where they were not intended.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad, natural-language prompts that can match ordinary user requests unrelated to this skill, causing unintended invocation. In an agent ecosystem, this can route tasks to the wrong workflow, increasing the chance of inappropriate web-search/API behavior, user confusion, or accidental execution of actions outside the user's intent.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description uses very broad matching terms like work-productivity, web, search, and practical workflow, which can cause the skill to activate for many unrelated user requests. Over-broad activation increases the chance that this skill hijacks routing from more appropriate or safer skills, leading to incorrect task handling and expanding the skill's effective authority beyond its intended scope.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords include highly generic words such as web, search, api, user, and alternative, which are common in everyday requests and likely to collide with unrelated prompts. This makes accidental invocation substantially more likely and can systematically misroute user tasks, especially in environments where skills are auto-selected from keyword matches.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example triggers use generic lead-ins like Help me and I need a practical workflow, which model broad activation patterns and reinforce accidental matching behavior. Even if illustrative, these examples teach invocation mechanisms that are not sufficiently scoped to the skill's intended domain, increasing unintended use.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger keywords are overly broad and include common terms like 'web', 'search', 'api', and 'user', which can cause the skill to activate for unrelated everyday requests. This increases the chance of unintended routing, prompt-context pollution, and accidental invocation of workflow behavior in situations where the user did not request this skill.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt uses broad, everyday trigger terms like work-productivity, tavily, web, and practical help without clear boundaries for when the skill should activate. Because implicit invocation is enabled, this can cause the skill to be pulled into unrelated conversations, increasing the chance of prompt-scope confusion, unintended tool use, or user redirection into this workflow without explicit intent.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences are broad, natural-language phrases that overlap with ordinary user requests rather than a narrowly scoped invocation pattern. This can cause the skill to activate unexpectedly in unrelated contexts, leading to misrouting, over-broad capability use, or accidental execution of workflow logic the user did not intend.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.