Back to skill

Security audit

Work Productivity Tavily Web Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk planning/helper skill, though its activation wording is broad enough that it may trigger for unrelated web or search requests.

Installers should treat this as a benign workflow-helper skill but should narrow activation if possible, preferably requiring Tavily or search-workflow-specific intent before use. Be aware that implicit invocation plus generic terms like web, search, api, and bug fix may cause the skill to appear in ordinary unrelated tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Confidence
90% confidence
Finding
The trigger sentence is broad and resembles ordinary user language, which increases the chance the skill will be invoked when the user did not explicitly intend to use it. In an agent environment, unintended invocation can route requests through the wrong workflow, causing irrelevant actions, confusing outputs, or accidental use of web/search capabilities.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The activation guidance does not clearly define when the skill should and should not activate, making the invocation boundary ambiguous. Because this skill is related to web/search workflows, accidental activation could expose downstream systems to unnecessary external-search behavior or cause the agent to prioritize this workflow over a more appropriate one.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are very broad and include common terms like 'web', 'search', 'api', and generic help requests, which can cause the skill to activate for unrelated everyday prompts. In an agent environment, this increases the chance of unintended routing, unexpected tool use, or the skill influencing tasks outside its intended scope.

Vague Triggers

High
Confidence
96% confidence
Finding
The manifest description includes very broad activation terms such as "work-productivity," "web," and "analysis," which can match a wide range of ordinary user requests unrelated to this skill’s actual scope. In agent systems that auto-route by keyword, this can cause the skill to activate unexpectedly, increasing the chance of prompt-surface expansion, incorrect tool usage, or unreviewed workflow injection into unrelated tasks.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger keyword list contains highly ambiguous terms such as "web," "search," "api," "user," and "bug fix," all of which are common across many benign requests. This makes accidental or adversarial invocation much easier, potentially causing the wrong skill to be selected and exposing downstream logic, instructions, or actions in contexts where they do not belong.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger sentences use broad conversational phrasing like "Help me" and "I need a practical workflow," without clearly defining boundaries for when this skill is appropriate. These examples can reinforce overbroad matching behavior in systems or authors, leading to scope creep and mistaken routing, though they are somewhat less dangerous than the manifest and keyword list because they are illustrative rather than primary activation metadata.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keyword list includes very broad, everyday terms such as "web", "user", "api", and "alternative", which can cause the skill to activate in many unrelated conversations. This creates routing ambiguity and can override more appropriate skills, leading to incorrect actions, irrelevant guidance, or accidental disclosure of context to an unnecessary workflow.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation condition in the description is vague and broad, stating the skill should be used when users mention common topics like work-productivity, web, or search, or when they need general workflow or analysis help. In a multi-skill agent environment, this can cause overmatching and unintended invocation, increasing the chance of misrouting user requests and producing unsafe or irrelevant outputs.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The manifest’s default prompt is overly broad and overlaps with ordinary user phrasing, which can cause unintended or implicit invocation of the skill in unrelated conversations. Because implicit invocation is enabled, this increases the chance the agent routes user requests into this skill without clear user intent, expanding attack surface and potentially exposing users to unexpected behavior.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger sentences are written as broad, natural-language phrases that overlap with ordinary user requests, increasing the chance the skill is invoked when the user did not explicitly intend it. In an agent ecosystem, unintended invocation can route user data and actions through the wrong workflow, causing prompt hijacking of task selection, irrelevant automation, or unsafe execution paths.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.