Back to skill

Security audit

Work Productivity Tavily Web Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with overly broad activation wording, but it does not request high-impact access, credentials, persistence, or hidden execution.

Before installing, be aware that this skill may be invoked for broad web/search/API productivity prompts. It appears safe as an advisory workflow helper, but tighter Tavily-specific trigger wording would reduce accidental use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentence is phrased so broadly that ordinary user requests about help, workflows, bug fixes, or hardening could unintentionally activate this skill. In an agent ecosystem, overly permissive activation increases the chance the wrong skill is invoked, causing unintended web-search behavior, incorrect routing, or inappropriate handling of user data and tasks.

Vague Triggers

Medium
Confidence
92% confidence
Finding
This trigger remains ambiguous about when the skill should be activated, because it describes a broad requirement instead of a precise invocation boundary. That ambiguity can cause overmatching with unrelated productivity or web-search requests, reducing agent reliability and potentially exposing user queries or context to an unnecessary skill path.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad, generic, and partially templated around common words like 'help me', 'practical workflow', 'user', and 'bug fix', which increases the likelihood that unrelated user requests will accidentally invoke the skill. In an agent ecosystem, unintended invocation can route user data or actions through the wrong workflow, causing confusion, incorrect tool usage, or unsafe execution paths.

Vague Triggers

High
Confidence
93% confidence
Finding
The skill description and activation guidance are broad enough to match many ordinary user requests unrelated to a narrowly scoped Tavily workflow helper. Over-broad routing can cause inappropriate skill invocation, which in agent systems can steer conversations, inject irrelevant workflow instructions, or bypass more appropriate safeguards by taking control in contexts it was not intended for.

Vague Triggers

High
Confidence
97% confidence
Finding
The keyword list contains vague, high-frequency terms such as 'web', 'search', 'user', and 'api' that are likely to appear in many benign prompts. In a skill-selection pipeline, these generic triggers can make the skill over-match and activate unexpectedly, increasing the chance of prompt-space capture and misrouting of agent behavior.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences use extremely common lead-ins like 'Help me' and 'I need', which provide weak activation boundaries and can train or bias matching systems toward ordinary conversational phrasing. While examples alone are less dangerous than the keyword list, they still reinforce an over-broad trigger surface that can cause accidental invocation in unrelated tasks.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description says it should activate for very broad terms like work-productivity, web, search, and via, without clear boundaries on user intent. This can cause the skill to trigger on unrelated requests, leading to incorrect routing, unexpected behavior, or inappropriate skill invocation in contexts the author did not intend.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes highly generic terms such as web, user, api, and alternative, which are common across many unrelated prompts. In systems that use keyword-based dispatch, this creates a high risk of accidental invocation, prompt-collision with other skills, and degraded reliability or unsafe tool selection.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example triggers use generic lead-ins like Help me, I need, and Use ... to handle, which do not meaningfully constrain when the skill should fire. These examples reinforce overbroad activation patterns and may train downstream routing or authors toward ambiguous matching behavior.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt invokes the skill with a very broad phrase and no meaningful trigger boundaries, which can cause the skill to be selected in contexts far beyond its intended scope. In an agent setting, over-broad auto-invocation increases the risk of prompt hijacking, irrelevant execution, and unsafe application of web/search workflows to sensitive tasks.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences are extremely broad and include common terms like 'help me', 'practical workflow', and generic references to work-productivity and web/search tasks. In an agent-routing context, this can cause unintended skill activation, leading the wrong skill to handle prompts, which may expose unrelated context, degrade safety controls, or produce actions the user did not intend.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.