Back to skill

Security audit

Ai Product Manager

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward product-management writing assistant with no executable code, hidden behavior, or unusual access requests.

This appears safe to install as a text-oriented product-management helper. As with any PM or analytics assistant, avoid sharing confidential customer data, unreleased strategy, or sensitive business metrics unless you intend that information to be used in the conversation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation examples are very broad, natural-language phrases such as asking for a PRD or competitor analysis, without any explicit trigger boundaries or scope constraints. In environments where skills are auto-selected from user intent, this can cause unintended activation, route ordinary conversation into this skill unexpectedly, and expose user inputs or produce actions under the wrong skill context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.