Cpo Advisor

Security checks across malware telemetry and agentic risk

Overview

This is a coherent product-strategy advisory skill with disclosed local analysis scripts and no evidence of hidden data access, persistence, or destructive behavior.

Reasonable to install if you want product strategy and CPO-style analysis. Treat the proactive advice as guidance, and avoid putting unnecessary customer PII or highly confidential business data into the optional JSON inputs for the local scripts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description is broad and keyword-heavy, covering many common product-strategy terms such as roadmap, PMF, portfolio prioritization, and product organization. In agent-routing systems, this can cause over-selection of the skill in loosely related contexts, leading to inappropriate delegation, reduced answer quality, and unintended access to additional context files or tools.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The proactive trigger section instructs the skill to surface itself based on broad organizational signals like declining NPS, lack of user research, or feature-request buildup, without clear gating for certainty or user intent. This increases the chance of unsolicited activation in marginally relevant conversations, which can bias workflows and crowd out more appropriate specialist skills.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal