Back to skill

Security audit

Product Validation Planner

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only product validation planning skill with some broad activation wording but no hidden execution, data access, persistence, or destructive behavior.

Installers should be aware that the skill may activate on broad product or business-planning language; tightening trigger wording would improve routing, but the artifact itself is documentation-only and does not appear to access data or run commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentence is broad enough to match many ordinary business or planning requests, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of inappropriate context capture, prompt interference, or the skill steering unrelated conversations into its workflow without clear user intent.

Vague Triggers

Medium
Confidence
94% confidence
Finding
This activation pattern is ambiguous and lacks precise criteria for when the skill should engage, making accidental invocation likely. In an agent environment, ambiguous triggers can override more appropriate skills or cause the model to follow domain-specific instructions in unrelated contexts, reducing reliability and potentially expanding the blast radius of any unsafe skill behavior.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are very broad and map to common business/product requests, which can cause this skill to activate in situations far beyond its intended scope. Over-broad activation increases the chance of prompt-routing mistakes, unintended interception of unrelated user tasks, and unsafe delegation if downstream skill behavior is stronger than expected.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description is broad enough to match many ordinary business, product, and operations requests, which can cause the agent to invoke this skill outside its intended niche. Overbroad routing increases the chance of inappropriate tool selection, prompt-surface expansion, and lower-quality or policy-bypassing behavior if the skill supersedes more suitable specialized skills.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords and examples are vague, generic, and highly reusable across a large fraction of normal startup or product conversations. This makes accidental or excessive activation likely, which can interfere with correct skill routing and allow this skill to dominate unrelated requests under broad terms like 'prototype,' 'saas,' or 'validation.'

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger keywords and sample invocations are broad enough to match many ordinary product or startup conversations, which can cause the skill to activate outside its intended scope. Over-broad routing increases the chance that users are steered into this workflow when another skill or a neutral response would be more appropriate, degrading safety and reliability of tool selection.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The front-matter description says to use the skill for broad categories like business-and-operations, product idea, validation, prototype, and saas, without strong limiting conditions. This can lead to unintended invocation across a wide range of normal business queries, creating prompt-routing ambiguity and increasing the risk of inappropriate or low-quality assistance.

Natural-Language Policy Violations

High
Confidence
80% confidence
Finding
The file is entirely in Chinese and does not offer user language selection or fallback behavior, which can force a locale choice regardless of user preference. This is primarily a usability and correctness risk: users may receive inaccessible instructions or the system may misroute based on locale-specific content, though it is not a direct security exploit by itself.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The default prompt uses a broad, ambiguous invocation phrase that can cause the skill to be triggered in contexts beyond the author's intended scope. Combined with allow_implicit_invocation=true, this increases the chance of unintended activation, context mixing, or the skill influencing conversations where the user did not clearly request it.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentence starts with the very broad phrase "Help me," which is likely to match many ordinary user requests unrelated to product validation. In an agent-routing context, this can cause unintended skill activation, leading to prompt/skill confusion, irrelevant guidance, or overshadowing of more appropriate skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The phrase "I need a practical workflow for ..." is still generic enough to match a wide range of requests unless paired with strict product-validation qualifiers. This increases the chance of accidental invocation and misrouting, especially because the skill is positioned broadly across business, prototype, SaaS, and implementation support.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.