Back to skill

Security audit

Work Productivity Tavily Web Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow skill with broad activation wording but no hidden execution, credential handling, persistence, or destructive behavior.

Before installing, consider narrowing or disabling implicit invocation so the skill only activates for explicit Tavily or web-search workflow requests. The inspected artifacts do not show hidden commands, data collection, credential use, or destructive behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger phrases are broad, generic, and closely resemble ordinary user requests, which increases the chance that the skill activates outside its intended scope. In an agent environment, this can cause unintended routing of unrelated tasks into this skill, leading to incorrect tool use, workflow hijacking, or confusion about which instructions govern the interaction.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and closely resemble normal user requests, which can cause the skill to activate in situations far outside its intended scope. In an agent ecosystem, this increases the chance of unintended invocation, prompt-routing confusion, and execution of the wrong workflow on unrelated tasks, reducing safety and predictability.

Vague Triggers

High
Confidence
94% confidence
Finding
The skill description is broad enough to match many ordinary requests because it includes generic domains and outputs like 'workflow', 'artifact', 'checklist', and 'analysis'. Over-broad routing can cause unintended invocation of this skill, which may override more appropriate skills, create prompt-surface expansion, and increase the chance that unrelated user input is processed under the wrong instructions.

Vague Triggers

High
Confidence
97% confidence
Finding
The keyword list contains very generic triggers such as 'web', 'via', 'user', 'api', and 'bug fix', any of which appear in many unrelated conversations. This makes accidental invocation highly likely, which can misroute tasks, interfere with least-privilege skill selection, and expose users to irrelevant or conflicting instructions at scale.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example triggers use generic phrasing like 'help me' and 'I need a practical workflow' without defining what distinguishes this skill from many other productivity or implementation helpers. Ambiguous examples train broad activation behavior and can cause the skill to capture requests outside its intended scope, reducing reliability and potentially masking safer or better-matched skills.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger list includes very broad generic terms such as "web", "search", "api", and "user", which can cause the skill to activate for many unrelated requests. Over-broad activation can misroute user tasks, override more appropriate skills, and increase the chance that the agent follows an irrelevant workflow in sensitive contexts.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description says to use the skill when a user asks for broad categories like work-productivity, web, or search, or needs practical support, but it does not clearly bound when the skill should or should not activate. Ambiguous scope increases accidental invocation and can lead to irrelevant or unsafe task handling if the agent selects this skill in contexts it was not designed for.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The default prompt is broad and keyword-heavy, making accidental activation plausible during ordinary user requests about productivity, web search, or Tavily-like workflows. This can cause the wrong skill to be invoked without clear user intent, which increases the risk of unintended prompt injection exposure, incorrect task routing, or overbroad tool use.

Vague Triggers

Medium
Confidence
96% confidence
Finding
Implicit invocation is enabled, but the file does not define tight trigger constraints or disambiguation rules. In combination with the broad prompt, this raises the likelihood that the skill activates on loosely related requests, potentially steering conversations or actions in ways the user did not intend.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases are broad, conversational, and include common words like 'help me' and 'I need a practical workflow', which can cause the skill to activate outside its intended scope. In an agent environment, this creates prompt-routing risk: unrelated user requests may be captured by this skill, leading to inappropriate handling, policy bypass through misrouting, or unintended use of web/search workflows.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.