Back to skill

Security audit

Work Productivity Tavily Web Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

The skill is not destructive, but it needs review because it can be automatically selected for many unrelated web, search, API, user, or bug-fix requests.

Review the invocation settings before installing. This skill appears safe as a manual Tavily-style workflow helper, but automatic selection should be narrowed or disabled so it does not steer unrelated web, API, or bug-fix tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and include common terms like 'help me', 'practical workflow', and product/domain words that could match many unrelated user requests. In an agent-routing context, this can cause unintended invocation of the skill, leading to incorrect tool selection, unnecessary exposure of workflow behavior, or execution in contexts the user did not intend.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests about workflows, bug fixing, or hardening, which can cause the skill to activate outside its intended scope. In an agent ecosystem, overbroad activation increases the chance of prompt-routing collisions, unintended tool use, and surprising behavior that may expose data or bypass safer, more specific skills.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description is broad enough to match many ordinary requests involving work, web, search, APIs, or bug fixes, which can cause unintended auto-activation. In an agent system, over-broad routing can silently inject irrelevant or lower-quality instructions into unrelated tasks, increasing the chance of unsafe behavior, user confusion, or policy bypass through misrouting.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list contains highly generic terms such as 'web', 'search', 'api', 'user', and 'bug fix', which are common across many benign requests. This makes accidental invocation likely and can let the skill influence tasks far outside its intended scope, creating routing ambiguity and compounding downstream safety issues.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases are written in generic natural language and do not establish clear activation boundaries, so they normalize broad matching behavior. In practice, this increases the likelihood that implementations or maintainers will treat loosely related requests as in-scope, causing unintended skill selection.

Vague Triggers

High
Confidence
94% confidence
Finding
触发关键词包含非常常见且高频的词,如“web”“search”“api”“user”“alternative”“bug fix”,会让该技能在大量无关对话中被误触发。误触发会导致代理偏离用户本意、错误注入该技能的工作流约束或输出模板,从而扩大错误自动化和不当操作的风险。

Vague Triggers

Medium
Confidence
88% confidence
Finding
技能描述将适用范围表述得很宽泛,如“work-productivity, tavily, web, search, via”或“需要实用流程、产物、检查清单、分析或实现支持时使用”,但没有给出清晰边界或不适用场景。对于自动技能选择系统,这会造成范围蔓延,使该技能在与 Tavily 工作流仅弱相关的请求中被启用,增加错误建议、上下文污染和流程劫持的可能性。

Vague Triggers

Medium
Confidence
86% confidence
Finding
示例触发句复用了宽泛且不精确的描述,没有展示能够有效区分适用/不适用场景的触发方式。由于许多编排器会参考示例进行匹配或提示扩展,这类示例会进一步放大误触发面,使技能在普通“help me”类请求中被不当地调用。

Vague Triggers

High
Confidence
96% confidence
Finding
The default prompt and description use extremely broad, everyday language such as 'help me' and common productivity/search terms, which can match many unrelated user requests. In combination with a skill-routing system, this creates a prompt-squatting risk where the skill may be invoked unexpectedly and influence tasks outside its intended scope.

Vague Triggers

High
Confidence
98% confidence
Finding
Enabling implicit invocation without clear trigger constraints allows the platform to auto-select this skill based on ambiguous user language. Because this skill is described with broad terms spanning productivity, web, search, workflow, checklist, analysis, and implementation support, it can be pulled into many conversations unintentionally, increasing the chance of unauthorized context influence or skill hijacking.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence starts with a generic phrase like 'Help me' and then embeds a long requirement description, making activation criteria overly broad and likely to match ordinary user requests that were not intended for this skill. In an agent-routing context, this can cause accidental invocation, irrelevant behavior, and increase the chance that the skill is selected in contexts involving web/search tasks without clear user intent.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The second trigger sentence ('I need a practical workflow for ...') is still framed as a common everyday request and does not meaningfully constrain scope, so many unrelated productivity or workflow requests could activate the skill. Because the skill concerns web/search workflows, over-triggering can misroute users into search-oriented behavior and reduce safety by applying the wrong workflow to the wrong task.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.