Back to skill

Security audit

Product Validation Planner

Security checks for vulnerabilities and agentic risk

Overview

This is a low-risk planning skill for product idea validation, with no executable code or sensitive access, though its activation wording is broader than ideal.

Install this if you want structured help validating product ideas or prototypes. Be aware that it may be invoked by broad startup or product wording, so explicitly invoke or avoid it depending on whether you want product-validation planning help.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad enough to match many ordinary product, startup, or workflow requests, which can cause the skill to activate outside its intended scope. Overbroad activation is dangerous because it can override more appropriate skills, steer users into a predefined workflow without clear consent, and increase the blast radius of any unsafe behavior contained in the skill instructions.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad enough to match many ordinary product, business, and startup-related requests, which can cause the skill to activate in situations the user did not explicitly intend. In an agent environment, over-broad activation increases the chance of inappropriate tool/skill selection, confusing outputs, and unsafe delegation of user tasks to a workflow that may not fit the request.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords are broad enough to match many ordinary product or startup conversations, which can cause the skill to activate outside its intended scope. Over-broad activation is dangerous because it can hijack routing, suppress more appropriate skills, and increase the chance that users receive generic or mis-scoped guidance without explicit intent to invoke this capability.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example triggers use natural, everyday wording that is extremely general and therefore likely to match routine user requests unrelated to this specific skill. This increases unintended activation risk and can lead to incorrect tool selection, especially in environments where trigger phrases are used for automated routing.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger keywords are broad, generic business terms such as 'validation', 'prototype', 'saas', and 'startup', which can match many unrelated requests. This can cause unintended invocation of the skill, leading to over-collection of user context, misrouting, or the skill influencing conversations outside its intended scope.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The example trigger phrases are vague and effectively mirror normal user language, without clear boundaries for when the skill should or should not activate. This increases the chance of accidental triggering in unrelated contexts, which can produce irrelevant guidance or cause the agent to apply the wrong workflow to a user request.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt uses a broad, ambiguous invocation phrase tied to a wide set of business/product tasks without clear trigger boundaries. This can cause the skill to be invoked in contexts the user did not explicitly intend, increasing the chance of prompt-routing mistakes, over-collection of context, or unauthorized execution of business-planning behavior.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentence begins with a very broad everyday phrase ('Help me ...'), which can cause the skill to activate for many unrelated user requests. Overbroad activation increases the chance of unintended routing, context confusion, and inappropriate invocation of this skill when a different skill or a general assistant response would be safer and more accurate.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The phrase 'I need a practical workflow for ...' is still too generic and lacks clear boundaries on when this skill should be invoked. In an agent environment, ambiguous triggers can cause over-selection of this skill for broad workflow requests unrelated to product validation, reducing reliability and potentially bypassing more appropriate specialized handling.

Static analysis

No suspicious patterns detected.