Workflow Builder Lite

Security checks across malware telemetry and agentic risk

Overview

This skill is an instruction-only workflow helper with broad but disclosed automation abilities and user confirmation for higher-risk steps.

Before installing, understand that this skill can help an agent run saved workflows that may include API calls, agent actions, shell commands, and file writes. Review each workflow before approving it, and only confirm shell commands or file writes when the exact command or content is expected and trusted.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The quick-command triggers are very generic (for example, phrases like "lag workflow", "kjør {name}", and "rediger {name}") and are not scoped to an explicit invocation boundary, trusted mode, or disambiguation step. In a conversational agent, broad triggers can cause accidental activation or prompt-injection-style steering where unrelated user text is interpreted as a command to create, edit, list, or execute persisted workflows, especially given this skill can chain API calls, file writes, and shell commands.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal