Back to skill

Security audit

Pm Workbench

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only product-management assistant skill with broad activation wording but no code, credential access, background behavior, or hidden data handling.

Before installing, expect this skill to influence a wide range of PM, interview, roadmap, experiment, and growth-strategy conversations. If you only want narrow template generation, consider tightening trigger keywords, but no malicious or high-impact behavior was found in the inspected artifacts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description is very broad and explicitly says to use it whenever the user asks about product management, PM advice, roadmaps, experiments, interviews, or growth strategy. That creates a real risk of unintended activation in ordinary conversations, which can inject the skill’s strong persona and workflow into contexts where the user did not clearly request this tool. While this is not directly malicious, it increases prompt-scope exposure and can steer conversations unexpectedly.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keyword list includes highly generic terms such as 'PM', '面试', '产品经理', and '需求分析', which are common in normal conversation and likely to collide with unrelated requests. This makes accidental invocation substantially more likely, causing the skill to load in contexts where it may override or bias the assistant’s default behavior. In this skill’s context, the wide range of PM workflows and persona instructions makes unintended activation more impactful than a narrowly scoped template-only skill.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The activation examples are broad natural-language phrases like '帮我模拟面试' and '我的面试要准备了', which can easily appear in ordinary conversation and unintentionally trigger the skill. This increases the risk of incorrect routing, unexpected behavior, and prompt/context injection exposure because the skill may activate when the user only wants general advice rather than this specific workflow.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.