Back to skill

Security audit

Work Productivity Tavily Web Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation language but no hidden execution, credential access, persistence, or destructive behavior.

Installers should be aware that this skill may activate on broad web/search/API phrasing; use explicit skill invocation when needed and review outputs as workflow advice, not as an authorization for automatic actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad, natural-language sentences that overlap with ordinary user requests rather than narrowly scoped invocation syntax. This can cause unintended skill activation, which is risky for a web/search workflow helper because it may steer conversations into external-search-oriented behavior when the user did not explicitly request this skill.

Vague Triggers

High
Confidence
90% confidence
Finding
The trigger phrases are extremely broad and include common terms like "web", "search", "api", and generic help-request patterns, making the skill likely to activate on ordinary unrelated user requests. In an agent environment, this can cause unintended routing or invocation, which may override more appropriate skills, confuse task handling, or expose users to workflows they did not explicitly request.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The manifest description uses broad activation terms such as "work-productivity," "web," "search," and "practical workflow" that can match many unrelated user requests. In agent routing systems, overbroad matching can cause unintended skill invocation, leading the wrong instructions or workflows to influence responses and increasing the attack surface for prompt/skill hijacking.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list includes ambiguous everyday terms like "web," "search," "user," and "via" without scope constraints, making accidental or excessive activation likely. If this skill is selected for unrelated prompts, it can override more appropriate skills or inject irrelevant process guidance into normal conversations.

Vague Triggers

Low
Confidence
87% confidence
Finding
The example triggers rely on generic lead-ins like "Help me" and "I need," which do little to distinguish this skill from ordinary requests. While less severe than the broad manifest and keyword issues, these examples reinforce weak routing boundaries and can contribute to mis-selection in systems that learn or mirror trigger phrasing.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description includes very broad trigger terms such as work-productivity, web, and search without strong scoping constraints. This can cause the skill to activate for many unrelated user requests, leading to prompt hijacking of routing behavior, unintended disclosure of irrelevant instructions, or lower-quality task handling when the wrong skill is selected.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list contains common terms like web, search, api, user, and alternative that are likely to appear in many unrelated prompts. In an agent environment, such overbroad matching increases accidental invocation risk, which can interfere with tool routing and cause the agent to follow an irrelevant workflow instead of the correct specialized skill.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt is broadly phrased in everyday language and can be implicitly invoked for a wide range of generic user requests (e.g. work-productivity, workflow help, implementation support) without clear boundaries. Because implicit invocation is enabled, this increases the chance of unintended routing or over-triggering, causing the agent to activate in contexts the user did not specifically intend.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences are extremely broad and include generic phrases like 'Help me' and 'I need a practical workflow,' which can cause the skill to activate for unrelated requests. In an agent environment, overbroad activation increases the chance of inappropriate routing, context capture, or execution of a workflow the user did not actually intend to invoke.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.