Back to skill

Security audit

Work Productivity Tavily Web Workflow Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style workflow helper with no executable code or hidden data access, but its auto-invocation terms are overly broad.

Before installing, be aware this skill may activate on broad search, API, workflow, or bug-fix requests. It appears safe as a documentation helper, but users or maintainers should narrow the triggers to explicit Tavily or web-search workflow requests to reduce accidental use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentences are broad, repetitive, and include generic terms like 'help me', 'practical workflow', and a long requirement description that could match unrelated user requests. In an agent ecosystem, this increases the chance of unintended skill invocation, causing the wrong workflow to run, which can mis-handle user data, produce irrelevant actions, or bypass the user's actual intent.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match ordinary requests about work productivity, web search, APIs, or bug fixing, which can cause the skill to activate in contexts the user did not intend. In an agent ecosystem, this creates prompt-routing confusion and increases the chance that a less appropriate or less safe workflow is injected into unrelated tasks.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description is broad enough to match many ordinary requests, including generic workflow, web, search, API, and implementation-support asks. In an agent environment, this can cause unintended activation and prompt-scope capture, where the skill influences tasks outside its intended niche and may override more appropriate or safer skills.

Vague Triggers

High
Confidence
98% confidence
Finding
The keyword list includes very generic terms such as 'web', 'search', 'api', 'user', and 'bug fix', which are common across a large fraction of benign tasks. This greatly increases accidental invocation risk, enabling the skill to intercept unrelated requests and shape agent behavior in contexts the user did not intend.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example triggers rely on broad everyday phrasing and effectively teach the router to activate on underspecified requests. Because they do not define boundaries or required context, they reinforce overmatching behavior and make accidental skill selection more likely during normal user interactions.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are overly broad and include common terms such as 'web', 'search', 'api', and 'user', which can cause the skill to activate in many unrelated conversations. This increases the chance of unintended routing, context hijacking, or the skill being invoked when its instructions are not relevant, reducing safety and predictability.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description says to use the skill when a user mentions broad categories or needs general support, but it does not clearly define boundaries for activation. Ambiguous invocation criteria can make orchestration systems select this skill too often, leading to misfires and possible interference with more appropriate skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
Using generic phrases like 'Help me' and 'I need' in trigger examples normalizes very common language as activation cues. In systems that learn or match against examples, this can broaden triggering behavior beyond the intended scope and contribute to accidental invocation.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt contains broad, everyday trigger terms such as 'help me' and generic workflow-related language, which can cause the skill to be invoked in contexts far beyond its intended Tavily-specific use case. This increases the risk of prompt-surface expansion, accidental routing, and unintended exposure of the skill's behavior in unrelated user requests.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without clear activation constraints allows the platform to auto-select this skill based on vague semantic overlap, even when the user did not intend to use it. Combined with the broad productivity/search framing in the metadata, this can cause over-invocation, prompt hijacking of unrelated tasks, and unintended influence over agent behavior.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger sentence is broad enough to match ordinary user phrasing and may cause the skill to activate outside its intended Tavily/web-workflow scope. Over-broad activation can route unrelated requests into this skill, creating prompt-scope confusion and increasing the chance of unintended tool use, misleading outputs, or policy bypass through misclassification.

Vague Triggers

Medium
Confidence
89% confidence
Finding
This trigger pattern uses a generic request form without clear boundaries, so many unrelated requests could satisfy it. In an agent-routing context, that can cause incorrect skill selection and expose users to workflow steps, assumptions, or actions that do not fit the request, reducing safety and reliability.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.