Back to skill

Security audit

Demand Discovery AI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed startup-demand validation connector that sends idea details to a named hosted service and does not show hidden persistence, destructive actions, or credential misuse.

Install this only if you are comfortable sending startup idea details, problem statements, solution descriptions, and possibly an email address to Demand Discovery AI's hosted service. Review any paid checkout link yourself before purchasing; the artifact does not indicate automatic payment or autonomous outreach.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation description is broad enough to trigger on many generic startup-advice or market-research requests, which can route users into a vendor-specific workflow and external MCP endpoint even when they did not explicitly ask for this product or service. In context, that increases the chance of over-collection of idea details and unnecessary exposure to a third-party service, especially because the skill strongly instructs the agent to use hosted tools rather than answer directly.

Static analysis

No suspicious patterns detected.