Back to skill

Security audit

Product Validation Planner

Security checks across malware telemetry and agentic risk

Overview

This is a product-validation planning skill with broad activation wording, but it contains no executable code, hidden data access, persistence, or privileged behavior.

Installers should be aware that this skill may activate for general startup, product, validation, or prototype requests because its trigger wording is broad. Review or narrow the triggers if precise routing matters, but the artifact itself does not show hidden behavior, credential access, persistence, or destructive actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentence is phrased so broadly that it can activate on ordinary user language rather than a clearly bounded skill-invocation pattern. In an agent ecosystem, ambiguous activation can cause unintended routing to this skill, leading the agent to apply business-planning instructions when the user did not explicitly request them, which increases the chance of prompt-surface abuse or incorrect task handling.

Vague Triggers

Medium
Confidence
92% confidence
Finding
This trigger phrase is insufficiently scoped and can match many benign requests for a 'practical workflow,' causing the skill to be selected outside its intended context. While the content here is not directly harmful, ambiguous invocation broadens the attack surface for misrouting, unintended instruction precedence, and user confusion in multi-skill agent environments.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are broad enough to match generic business, product, validation, prototype, and startup requests, which can cause the skill to activate outside its intended scope. Over-broad invocation increases the chance of inappropriate routing, unexpected behavior, or prompt-surface expansion when unrelated user input is interpreted as a request to use this skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description is very broad and targets common requests such as product ideas, validation, prototypes, and implementation support. This can cause the skill to activate in many unrelated situations, increasing the chance that it overrides more specific skills or inserts unreviewed guidance into general business workflows.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger keywords include vague, high-frequency terms like 'validation', 'prototype', 'saas', and 'startup' without qualification. In a skill-routing system, such generic keywords can lead to excessive invocation, misrouting, or prompt-surface expansion, which is risky because the skill may handle requests it was not intended to govern.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description is extremely broad and includes common business terms like product idea, validation, prototype, and SaaS, which can cause the agent to invoke this skill for many loosely related requests. Overbroad routing increases the chance of unintended activation, causing the model to follow an irrelevant workflow, mishandle user intent, or expose users to inappropriate business guidance when another skill or default behavior would be safer.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The trigger keywords and example trigger phrases are highly generic and unconstrained, making accidental invocation likely across a wide range of normal startup or operations conversations. Because the examples also encourage explicit tool invocation with a broad mandate, the skill may override more suitable skills or steer responses into a rigid validation workflow even when the user's request is only tangentially related.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The default prompt is broad and maps to common founder/product-assistance language without meaningful scoping or guardrails, which can cause the skill to be invoked in situations the user did not clearly intend. Because implicit invocation is enabled, this increases the chance of over-triggering, unexpected routing, and accidental exposure of user context to a skill that was not explicitly selected.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match ordinary product or business questions, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of prompt-routing mistakes, unintended tool use, or an adversarial user steering the agent into this skill when another safer or more specific path should apply.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.