Back to skill

Security audit

Work Productivity Tavily Web Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

The skill is a documentation-only workflow helper with overly broad activation wording but no code execution, persistence, or sensitive access.

Installers should be aware that this skill may activate on general web/search/productivity phrasing. It is otherwise a low-impact documentation helper; consider narrowing triggers or disabling implicit invocation for cleaner routing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match common user requests about productivity, web search, or bug fixing, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad activation can route unrelated prompts into this skill, creating prompt-scope confusion and increasing the chance of unsafe or unintended actions based on irrelevant instructions.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad, repetitive, and include generic terms like 'help me', 'practical workflow', and product-category keywords that can match many unrelated user requests. In an agent environment, this can cause unintended skill activation, leading the system to invoke web-search or workflow behavior outside the user's actual intent and increasing the chance of inappropriate data handling or confusing automation.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list is overly broad and includes generic terms like "web," "search," "api," and "user," which can cause the skill to activate in many unrelated conversations. Unintended activation can divert agent behavior, introduce irrelevant instructions into workflows, and increase the chance that this skill influences tasks outside its intended scope.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The manifest description uses broad invocation language such as "Use when a user asks for work-productivity, tavily, web, search, via," which effectively scopes the skill to a very large set of common requests. This can lead to over-selection of the skill, causing instruction collision, reduced predictability, and possible misapplication in contexts where the skill's workflow is not appropriate.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords include highly generic terms such as "web", "search", "api", and "user", which can overlap with a large fraction of ordinary conversations. This makes unintended skill activation plausible, causing the agent to apply the wrong workflow, expose irrelevant capabilities, or interfere with higher-priority instructions in unrelated contexts.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says the skill should be used when a user asks for broad categories like work-productivity, tavily, web, search, or wants practical help, but it does not define strong boundaries for when the skill should not activate. Ambiguous activation criteria increase the chance of accidental invocation and context bleed into tasks that only loosely resemble the intended use case.

Vague Triggers

Medium
Confidence
91% confidence
Finding
Example trigger phrases starting with common expressions like "Help me" and "I need" are likely to match ordinary user requests that have nothing to do with this skill. In a skill-selection system, these examples can unintentionally bias routing toward this skill, increasing misfires and reducing reliability of intent classification.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt uses a very broad natural-language invocation phrase with common terms like 'help me' and generic workflow wording, which can cause unintentional activation in ordinary user conversations. In combination with agent routing, this increases the risk that the skill is invoked outside the user's intent, exposing its behavior or downstream tools in contexts where they were not explicitly requested.

Vague Triggers

Medium
Confidence
94% confidence
Finding
Enabling implicit invocation without strong activation constraints allows the platform to route ordinary requests to this skill based on loosely related terms like work, web, search, or productivity. Because this skill is broadly described and adjacent to web-search workflows, accidental invocation can expand the attack surface for prompt misuse, unintended data handling, or unsafe tool usage.

Vague Triggers

High
Confidence
90% confidence
Finding
The trigger sentences are broad enough to match ordinary user phrasing such as asking for a practical workflow or help with web/search-related tasks, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad routing increases the chance of misapplication, prompt collisions, and unintended handling of unrelated requests, reducing reliability and potentially exposing users to incorrect or unsafe automation paths.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.