Back to skill

Security audit

Work Productivity Tavily Web Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad auto-invocation wording, but it does not install code, request credentials, persist, or perform actions by itself.

Installing this skill mainly affects routing and guidance quality. Review whether you want a broadly triggered Tavily/web workflow helper enabled implicitly; users who prefer precise activation should narrow the keywords or require explicit invocation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad, natural-language prompts that could activate the skill in situations beyond the author's intent, especially when users mention generic workflow, bug-fix, or Tavily-related needs. In an agent ecosystem, ambiguous activation boundaries can cause unintended invocation, incorrect tool selection, or prompt-surface expansion that increases the chance of unsafe or irrelevant actions.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests about help, workflows, or bug fixes, which can cause the skill to activate unintentionally. In an agent ecosystem, overbroad activation can route unrelated prompts into this skill, causing prompt hijacking of task selection, unexpected data handling, or unreliable behavior across normal conversations.

Vague Triggers

High
Confidence
97% confidence
Finding
The manifest description uses very broad terms like "work-productivity," "web," "search," and "practical workflow" that can match many ordinary user requests unrelated to this specific skill. This increases the chance of accidental or overbroad activation, causing the agent to route tasks into an unintended skill context and potentially override more appropriate, narrower workflows.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keyword list includes highly generic tokens such as "web," "search," "api," "user," and "alternative," which are common across a wide range of unrelated requests. Such ambiguous activation signals make unintended invocation likely, increasing misrouting risk and reducing the safety and predictability of agent behavior.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The example triggers are written as broad everyday requests like "Help me" and "I need a practical workflow," with only loosely attached domain context. These examples encourage matching on common phrasing rather than clear capability boundaries, which can propagate unsafe activation behavior into downstream routing logic or authoring patterns.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description and activation guidance are broad enough that common terms like 'web', 'search', and 'via' could trigger the skill in unrelated conversations. This can cause unintended routing, leading the agent to apply the wrong workflow or expose users to outputs not suited to their actual task, reducing reliability and potentially bypassing safer, more specific skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes multiple generic, high-collision words ('web', 'search', 'api', 'user') without constraints, making accidental activation likely. In an agent environment, this can misroute broad categories of requests, causing incorrect tool selection and weakening predictability and safety controls built around precise skill invocation.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt is highly generic and expansive, which can cause the platform to invoke this skill for loosely related requests. That increases the chance of unintended routing, where user input is handled by a skill outside the user's expectations, potentially exposing context or producing unsafe workflow guidance in irrelevant situations.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without narrow constraints allows the system to auto-select this skill based on broad semantic matching rather than explicit user intent. In combination with the vague skill description, this can lead to over-triggering, unexpected use of the skill, and accidental disclosure of user context to an inapplicable workflow helper.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentence is extremely broad and includes generic phrasing like 'Help me' and 'I need a practical workflow,' which can cause the skill to activate for many unrelated user requests. Overbroad activation increases the chance of inappropriate routing, accidental invocation, and prompt-scope confusion where the agent applies this skill outside its intended Tavily/web-workflow context.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation guidance is underspecified and lacks clear boundaries, relying on broad keywords and expansive trigger examples rather than precise eligibility criteria. This makes the skill easier to misfire on ordinary productivity or web-related requests, which can lead to unintended behavior selection and reduce safety by bypassing more appropriate, narrower skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.