Back to skill

Security audit

Saas Indie Hacker Coach

Security checks across malware telemetry and agentic risk

Overview

This is a text-only SaaS coaching skill with no executable behavior, hidden access, or data movement, though its business advice can affect real payment and launch decisions.

Reasonable to install as a business coaching skill. Treat its recommendations about deposits, trials, pricing, launches, and exits as business advice to review carefully, and avoid sharing unnecessary confidential metrics or customer data unless needed for the specific coaching request.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger list contains broad phrases such as "MRR," "Acquire.com," and "Product Hunt launch" that commonly appear in general startup, finance, and product discussions. This can cause the skill to activate outside its intended indie-hacker niche, leading to misrouting and inappropriate business advice in unrelated contexts.

Vague Triggers

Low
Confidence
91% confidence
Finding
The engagement criteria span many adjacent business topics but define only a short refusal list, leaving activation boundaries under-specified. In practice, the skill may engage on broader startup or SaaS topics where specialized indie-founder assumptions do not apply, increasing the chance of irrelevant or poor-fit guidance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal