Back to skill

Security audit

Product Validation Planner

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed product-validation planning helper with no executable code, persistence, credential handling, or hidden data access.

Before installing, be aware that this skill may activate for broad product, startup, SaaS, prototype, or business-planning prompts. Review its outputs as planning advice, not validated market research; it does not appear to access private data or run code on its own.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence is broad enough to match many ordinary product or business requests, which can cause the skill to activate outside its intended niche. Overbroad activation increases the chance of unintended instruction injection into unrelated conversations, leading to inappropriate workflow steering or interference with safer, more specific skills.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation guidance lists broad keywords and trigger examples but does not define boundaries for when the skill should not run. Without clear scope and exclusions, the orchestrator may invoke this skill for common requests that only loosely relate to product validation, creating unnecessary exposure to skill instructions and reducing routing precision.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad enough to match common, non-specialized requests such as general help with workflows, ideas, or validation. This can cause the skill to activate outside its intended scope, leading to inappropriate routing, over-collection of user context, or unintended execution of business-planning behavior when the user did not explicitly request it.

Vague Triggers

High
Confidence
96% confidence
Finding
The skill description is broad enough to match many ordinary business, planning, prototype, and analysis requests, which increases the chance of unintended or overly frequent activation. Overbroad activation can route users into the wrong skill, causing prompt-scope confusion, reduced policy enforcement fidelity, and potentially exposing downstream resources or instructions that were only meant for narrower use cases.

Vague Triggers

Medium
Confidence
98% confidence
Finding
The trigger keywords like "business-and-operations," "product idea," "validation," "prototype," "saas," and "startup" are highly generic and commonly appear in benign user requests across many domains. This makes accidental invocation likely and can let this skill preempt more appropriate skills, expanding its operational scope beyond what was intended.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description is broad enough to match many ordinary product, startup, or operations requests, increasing the chance that the skill is invoked outside its intended scope. Overbroad routing can cause inappropriate workflow injection, irrelevant instructions, or unexpected handling of user requests, which is a real safety and quality risk even without overtly malicious content.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The keyword list uses very common terms like 'product idea', 'prototype', 'saas', and 'startup' without disambiguation, so the skill may trigger on many unrelated requests. This can lead to misrouting and untrusted skill instructions being applied where they do not belong, which becomes more dangerous because the workflow encourages proceeding with assumptions rather than clarifying scope first.

Natural-Language Policy Violations

High
Confidence
88% confidence
Finding
The file is entirely localized to zh-CN and does not offer user choice, fallback behavior, or justification for forcing this locale. In a multilingual environment, this can cause users to receive instructions they cannot reliably understand, increasing the risk of misunderstanding workflow steps, assumptions, or output requirements.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt invokes the skill with a very broad phrase tied to common business/product requests, which increases the chance of automatic or unintended routing into this skill. Combined with allow_implicit_invocation: true, the skill may activate in contexts where the user did not explicitly request it, causing overreach, prompt confusion, or unsafe delegation of planning tasks based on weak relevance.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentence is overly broad and can cause the skill to activate on generic user requests that only loosely relate to product validation. This increases the chance of inappropriate routing, prompt confusion, or untrusted skill invocation, especially in agent systems where trigger matching controls access to downstream behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.