Back to skill

Security audit

product-management

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate product-management skill, but it deserves review because it can handle sensitive customer/product data and write to connected tools without clear confirmation steps.

Review before installing if your workspace contains confidential roadmap, metrics, or customer feedback data. Use it with explicit instructions for which files or connectors it may access, redact personal/customer data where possible, and require confirmation of the Notion page or local filename before any report is written.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The README states the skill can be triggered through natural conversation with automatic matching, but it does not define clear activation boundaries, exclusions, or confirmation requirements. In an agent environment, this can cause unintended invocation during ordinary product discussions, leading to accidental processing of user data or execution of downstream skill behavior without explicit user intent.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The listed trigger keywords include highly generic phrases like 'roadmap', 'brainstorm', '用户反馈', and '用户故事', which are common in normal workplace conversation and lack contextual constraints. This increases the likelihood of false activation and unintended skill execution, especially because the skill covers many subfunctions under a single broad routing surface.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger phrases listed in the skill description include broad everyday expressions such as 'brainstorm' and '写PRD/需求文档', which can cause the skill router to activate on loosely related user requests. In an agent environment, overly broad routing can lead to unintended execution paths, unexpected file reads, or application of the wrong workflow without clear user intent.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The routing logic allows matching not only on explicit subskill keywords but also on vague 'scenes mentioned in the function description' without defining boundaries. This ambiguity can be exploited by crafted prompts to steer the agent into an unintended subskill, increasing the risk of wrong outputs, unnecessary data handling, or access to templates unrelated to the user's true request.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly supports analyzing uploaded user feedback data such as Excel, CSV, or text, but it does not warn users about privacy, personal data, or sensitive business information. In a product-management context, uploaded feedback commonly contains names, emails, account details, or proprietary customer comments, so silent ingestion increases data exposure and compliance risk.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill states that if a template requires generating a file, the agent should write it and then declare the artifact, but there is no requirement to notify or obtain approval from the user first. Unprompted file creation can overwrite existing work, create misleading artifacts, or persist sensitive content unexpectedly in the user's workspace.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The file is entirely in Chinese and does not offer a language choice or explicitly constrain the supported locale. In a general-purpose agent environment, this can cause users or downstream systems to misunderstand instructions, inputs, or outputs, leading to incorrect analysis, bad decisions, or unsafe automation behavior due to language mismatch.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs writing roadmap update reports into Notion but does not require an explicit user-facing disclosure or confirmation before sending potentially sensitive roadmap, milestone, dependency, and delay information to an external service. In a product-management context, this data can include confidential strategy and execution details, so silent export increases the risk of unintended data sharing.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill says it will automatically pull current sprint and issue data from Linear without a user-facing warning that external project-management data will be accessed. In this context, iteration tasks, blockers, and progress often contain sensitive internal operational information, so implicit retrieval can violate least surprise and organizational data-handling expectations.

Missing User Warnings

Low
Confidence
89% confidence
Finding
The skill explicitly instructs writing the generated analysis report into Notion, but it does not require explicit user confirmation, identify the destination workspace/page, or warn that external content will be modified. This creates a real integrity risk: an agent could publish incorrect, sensitive, or unintended analysis into a team knowledge base without sufficient user awareness or approval.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.