Product Owner

Security checks across malware telemetry and agentic risk

Overview

This is a coherent product-owner helper that stores product context locally and does not show hidden execution, exfiltration, or destructive behavior.

Install if you are comfortable keeping backlog, roadmap, sprint, stakeholder, and priority notes in ~/product-owner/. For sensitive products, choose opt-in-only assistance and periodically review or clear the local memory files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The setup instructs the skill to proactively offer help 'whenever you're working on backlogs or user stories' and to assist with sprint planning proactively, which can cause the skill to activate in broad, ordinary conversations without a clear user request. In an agent setting, this weak boundary can lead to overreach, unexpected persistence, or collection/storage of product context before the user has explicitly opted in.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal