Back to skill

Security audit

Work Productivity Tavily Web Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording but no hidden execution, credential access, persistence, or destructive behavior.

Installers should be aware that the skill may activate too often for ordinary web, search, API, or help requests. It is reasonable to use, but the publisher should narrow triggers to explicit Tavily/web-search workflow scenarios or disable implicit invocation to reduce misrouting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger examples are generic enough to match ordinary requests about help, workflows, bug fixing, or hardening, which can cause the skill to activate outside its intended narrow scope. In an agent ecosystem, overbroad activation can route unrelated user tasks into this skill, creating prompt-scope confusion and increasing the chance of unintended behavior or misuse of adjacent web/search capabilities.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad, natural-language sentences that overlap with ordinary user requests, which can cause the skill to be invoked unintentionally. In an agent ecosystem, overbroad activation can route unrelated tasks into this skill, leading to incorrect behavior, unnecessary tool use, or expanded exposure to web/search workflows the user did not explicitly request.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description is so broad that it can match many ordinary requests unrelated to the specific Tavily workflow use case. This increases the chance of unintended invocation, causing the agent to apply the wrong workflow, introduce irrelevant external-search behavior, or bypass more appropriate specialized skills.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keyword list contains vague terms such as 'web', 'search', 'user', and 'api' that are common across many benign requests. In agent routing systems, generic triggers can cause frequent accidental activation, leading to misrouting, overbroad tool use, or workflow confusion that degrades safety and reliability.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger phrases use everyday language and directly embed broad requirement text, which does not create clear activation boundaries for the router or user. This can normalize overly permissive triggering and make the skill fire in situations where a narrower, safer skill should handle the request.

Vague Triggers

Medium
Confidence
93% confidence
Finding
触发关键词包含大量高频、通用词(如 web、search、api、user),容易在与技能目标无关的普通对话中被误匹配并触发该技能。误调用会让代理在错误上下文中执行不相关流程,造成结果偏离、错误自动化决策,或把后续敏感操作建立在错误前提上。

Vague Triggers

Medium
Confidence
89% confidence
Finding
技能描述将适用范围表述得较宽,如“需要实用流程、产物、检查清单、分析或实现支持时使用”,但没有清晰边界,导致路由器或调用方难以判断何时真正应启用该技能。这会增加误选技能、覆盖更合适技能、以及在不恰当场景下输出不可靠建议的风险。

Vague Triggers

Low
Confidence
84% confidence
Finding
示例触发句使用了非常泛化的句式(如 Help me、I need a practical workflow),会训练或诱导上层系统把普通帮助请求也映射到该技能。其危险性低于直接宽泛关键词,但会放大误调用概率,降低整个技能路由系统的精度。

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt is highly generic and includes broad terms like 'help me' and common workflow language, which can cause the skill to match routine user requests that were not intended to invoke it. In combination with agent routing, this increases the chance of accidental invocation and prompt-scope bleed into unrelated tasks.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without tight trigger boundaries allows the skill to activate based on loosely related user language, especially given the broad productivity/search wording in the manifest. This can lead to unrequested tool routing, unintended handling of user data, and unpredictable agent behavior across ordinary prompts.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger sentences are broad, natural-language phrases that could match ordinary user requests and cause the skill to activate when the user did not explicitly intend to invoke it. In an agent environment, unintended invocation can misroute tasks, expose the skill to unrelated contexts, and create confusing or unsafe workflow execution, especially because the skill is positioned around web/search assistance and generalized implementation support.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.