Back to skill

Security audit

Work Productivity Tavily Web Workflow Helper

Security checks for vulnerabilities and agentic risk

Overview

This documentation-only Tavily workflow helper appears safe to install, but its broad automatic trigger wording may make it activate when users did not mean to use it.

Installers should be aware that this skill may be selected for ordinary web/search/workflow requests because its triggers are broad. Use explicit invocation for Tavily workflow help, or tighten the trigger wording before publishing in environments where accidental activation matters.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentences are broad, natural-language phrases that could match ordinary user requests and cause the skill to activate when the user did not explicitly intend to invoke it. In an agent environment, unintended invocation can route tasks through the wrong workflow, potentially changing tool usage, search behavior, or outputs in ways the user did not request.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are generic enough to match ordinary user requests about workflows, bug fixing, or web/search tasks, which can cause this skill to activate outside its intended scope. Over-broad activation increases the chance of unintended tool use, incorrect routing, and user confusion, especially for a skill tied to external-search-style workflows.

Vague Triggers

High
Confidence
94% confidence
Finding
The skill description and usage guidance are broad enough to activate on common terms like 'web', 'search', 'api', and 'user', which can cause unintended invocation outside the intended Tavily-style workflow domain. Over-broad routing increases the chance that this skill intercepts unrelated tasks and produces misleading or unsafe guidance in contexts where a more appropriate skill should have handled the request.

Vague Triggers

High
Confidence
97% confidence
Finding
The keyword list includes highly generic triggers such as 'web', 'search', 'api', 'user', and 'alternative', any of which are common across many benign requests. In an agent ecosystem, this can cause systematic overmatching, accidental tool selection, and prompt-routing confusion that degrades reliability and may expose users to incorrect actions or data handling paths not intended for their task.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases use broad everyday wording like 'help me' and 'I need a practical workflow' combined with repeated requirement text, but they do not define firm activation boundaries. These examples train users or orchestration layers toward permissive matching behavior, increasing the likelihood of unintended activation and incorrect handling of unrelated productivity or search requests.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger keywords are very broad and include common terms such as 'web', 'search', 'api', and 'user', which can easily overlap with unrelated conversations. This can cause the skill to activate outside its intended scope, leading to incorrect routing, confusion, or inadvertent use of this skill in contexts where more appropriate safeguards or tools should apply.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description defines activation in vague terms like users asking for 'work-productivity, tavily, web, search, via' or needing 'practical workflow' support, without clear boundaries. Because these conditions are underspecified, the orchestration layer may invoke the skill for a wide range of unrelated requests, increasing the chance of misexecution, irrelevant outputs, and unsafe task handling in the wrong context.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The default prompt uses a very broad, natural-language invocation phrase that overlaps with ordinary user requests about work productivity, Tavily, or web workflows. This increases the chance of unintended skill activation, causing the agent to apply this skill in contexts the user did not explicitly request, which can lead to prompt-scope confusion or unsafe delegation.

Vague Triggers

Medium
Confidence
97% confidence
Finding
Enabling implicit invocation without strong activation constraints allows the platform to auto-select this skill based on loosely related user wording. In a broadly described productivity/search skill, this creates a real risk of over-triggering, unintended tool usage, or routing user requests into a skill path they did not mean to invoke.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger sentences are broad, natural-language phrases that can match ordinary user requests rather than a clearly scoped invocation. This can cause unintended activation of the skill in unrelated contexts, increasing the chance that the agent applies the workflow when the user did not intend it, leading to confusion, misrouting, or unsafe automation chaining.

Static analysis

No suspicious patterns detected.