Back to skill

Security audit

Work Productivity Tavily Web Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only workflow helper with overly broad activation wording, but it does not install code, persist, escalate privileges, or handle credentials.

Installers should be aware that this skill may activate for generic web search or API requests because its triggers are broad. Review or narrow the trigger keywords if precise routing matters, but the inspected artifacts do not show automatic execution, credential handling, persistence, or destructive behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentences are broad, generic, and closely resemble normal user requests, which can cause the skill to activate unintentionally for unrelated prompts. In an agent environment, over-broad activation can misroute tasks, inject the skill’s workflow into conversations without clear user intent, and increase the chance that web-search or workflow behaviors run in inappropriate contexts.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad, generic, and partially mirror ordinary user requests, which can cause the skill to activate in unintended contexts. In an agent ecosystem, this increases the chance of misrouting user intent, unexpected tool use, or invocation of workflow logic when the user did not explicitly ask for this skill.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description uses very broad terms like 'work-productivity', 'web', 'search', 'workflow', 'artifact', and 'analysis', which can cause the skill to activate for many unrelated user requests. In an agentic environment, over-broad routing can misapply this skill, leading to incorrect handling of tasks, scope confusion, and reduced safety if users are steered into an unintended workflow.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords include vague, high-frequency terms such as 'web', 'search', 'via', 'api', and 'user' without qualifiers, making accidental invocation highly likely. This is dangerous because a generic keyword match can route unrelated requests into this skill, causing privilege overreach in task selection and unreliable or unsafe agent behavior at scale.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example triggers are framed with generic lead-ins like 'Help me' and 'I need', which do not establish meaningful routing constraints and reinforce broad activation behavior. In practice, this can train maintainers or routing systems to treat commonplace requests as matches, increasing false activations and lowering trust in skill boundaries.

Vague Triggers

High
Confidence
95% confidence
Finding
触发关键词包含大量高频、通用词,如 “web”、“search”、“api”、“user” 和 “bug fix”,会与许多无关请求重叠,导致技能被误触发。误触发会让代理在不适合的上下文中套用该技能流程,带来错误建议、范围漂移,或覆盖本应由更合适技能处理的任务。

Vague Triggers

Medium
Confidence
86% confidence
Finding
技能描述把适用范围写得过宽,既涵盖 work-productivity、web、search 等大类主题,又包含“流程、产物、检查清单、分析或实现支持”等泛化输出类型,但没有明确排除条件。这会增加路由歧义,使系统在边界模糊的请求上错误调用该技能,影响结果准确性与最小权限式的技能选择。

Natural-Language Policy Violations

Medium
Confidence
72% confidence
Finding
该技能文件为中文版本,内容未体现根据用户语言偏好切换输出,可能在多语言环境中默认以特定语言响应。这通常不是直接安全漏洞,但会造成误解、错误执行步骤或用户无法准确验证输出,在涉及配置、修复和安全加固时会放大操作风险。

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt uses a very broad, natural-language invocation phrase ('Use $work-productivity-tavily-web-workflow-helper to help me ...') that can overlap with ordinary user requests. In systems that support implicit or heuristic skill routing, this increases the chance of accidental invocation, unintended context exposure, or triggering the skill when the user did not explicitly intend to use it.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentences are extremely broad and resemble ordinary user phrasing, which can cause the skill to activate in situations far beyond its intended Tavily/web-workflow scope. Unintended invocation can override more appropriate skills, process unrelated user inputs, and increase prompt-surface exposure to adversarial or irrelevant content.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The keyword list includes generic terms like "web," "search," "api," "user," and "bug fix," which are too unspecific to safely gate activation. This creates a broad matching surface that can spuriously route many unrelated requests into this skill, reducing reliability and potentially exposing users to incorrect or mismatched workflows.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.