Back to skill

Security audit

Work Productivity Tavily Web Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only Tavily workflow helper with overly broad activation wording but no hidden execution, data access, persistence, or privilege changes.

Install only if you want a Tavily/web-search workflow planning helper. Consider narrowing or disabling implicit invocation because the current keywords may activate the skill for unrelated web, search, API, or productivity prompts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentences are extremely broad and include generic phrases like 'Help me' and 'I need a practical workflow', which can cause unintended activation in unrelated conversations. In an agent ecosystem, ambiguous auto-invocation can route user data or execution flow into the wrong skill, reducing reliability and potentially causing unsafe actions under the wrong context.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are extremely broad and generic, covering common terms like 'web', 'search', 'api', 'user', and 'bug fix'. In an agent ecosystem, this can cause the skill to activate in many unrelated contexts, leading to unintended invocation, prompt-surface expansion, and possible interference with more appropriate skills or workflows.

Vague Triggers

High
Confidence
94% confidence
Finding
The skill description and usage guidance are broad enough to match many ordinary requests involving generic terms like 'web', 'search', or 'via'. In an agent environment, this can cause unintended auto-selection, leading the wrong skill to run, which may confuse task routing, override more appropriate safeguards, or expose users to irrelevant workflow behavior.

Vague Triggers

High
Confidence
97% confidence
Finding
The keyword list contains highly generic terms such as 'web', 'search', 'via', 'api', and 'user' without contextual constraints. These terms are likely to collide with many unrelated prompts, increasing the chance of accidental invocation and creating a prompt-routing vulnerability where this skill may intercept requests it should not handle.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences use vague phrasing like 'help me' and 'I need a practical workflow' without clarifying what falls inside or outside the skill's scope. This reinforces overbroad matching behavior and makes it easier for unrelated requests to be interpreted as valid triggers, reducing routing precision and potentially bypassing better-targeted skills.

Vague Triggers

Medium
Confidence
92% confidence
Finding
触发关键词包含非常常见且高频的通用词,如“web”“search”“user”“api”“alternative”,且未附带足够的上下文约束,容易在与技能实际职责无关的普通请求中被误激活。误触发会导致错误路由、无关指令注入到任务流中,降低系统可靠性,并在多技能环境下扩大不必要的数据暴露或执行面。

Vague Triggers

Medium
Confidence
89% confidence
Finding
技能描述中的激活条件使用了宽泛表述,如“当用户提出 work-productivity, tavily, web, search, via”或“需要实用流程、产物、检查清单、分析或实现支持时使用”,但没有给出明确的任务边界、排除条件或领域限定。这会使编排器难以区分该技能与其他通用生产力/搜索类技能的适用范围,增加错误调用、权限扩散和不相关上下文处理的风险。

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt uses a long, generic natural-language invocation phrase tied to common concepts like work productivity, workflows, and practical help. Because implicit invocation is part of the skill design, broad phrasing increases the chance the skill is auto-triggered in situations the user did not specifically intend, which can cause inappropriate routing or prompt-context injection into unrelated tasks.

Vague Triggers

Medium
Confidence
96% confidence
Finding
Enabling allow_implicit_invocation without tight activation constraints allows the platform to invoke the skill based on ambiguous user language. In this skill, the subject matter is broad enough that many unrelated productivity or web-search requests could match, increasing the risk of unintended execution and cross-context behavior.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is written broadly enough that ordinary user requests containing common phrasing like 'help me' plus loosely related terms could activate the skill unintentionally. In an agent environment, over-broad invocation can route unrelated tasks into this skill, causing incorrect tool selection, confused execution, and increased exposure to any downstream web/search actions the skill may perform.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation guidance lacks precise boundaries and mixes broad category words with generic request templates, making the skill eligible for activation across a wide range of normal productivity or web-related requests. This is dangerous because ambiguous routing in multi-skill agents can produce unintended execution paths, lower reliability, and potentially invoke web-search-related behavior in contexts where the user did not ask for it.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.