Back to skill

Security audit

Product Validation Planner

Security checks across malware telemetry and agentic risk

Overview

This is a planning-only skill for product idea validation; its triggers are broad, but it does not request sensitive access or perform unsafe actions.

Installers should know this skill may activate for broad product or startup planning language, so it is best used when product validation planning is actually intended. It does not appear to run code, access private data, persist state, or modify systems.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are broad enough to match common product or workflow requests, which can cause the skill to activate outside its intended scope. In an agent system, over-broad activation can override more appropriate skills, leading to misrouting, unintended instruction precedence, or expanded exposure to any unsafe behavior present in the skill.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad enough to activate on generic business, startup, validation, prototype, or SaaS requests without clear boundaries or disambiguation. This can cause unintended skill invocation, steering users into this workflow when they did not explicitly request it, which is a prompt-routing and user-intent integrity issue rather than direct code execution risk.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description and use conditions are broad enough to match many ordinary product, business, and workflow requests, which can cause the skill to activate outside its intended niche. Over-broad activation increases the chance of inappropriate instruction injection into unrelated conversations and can override more suitable, narrower skills.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger keywords are highly generic terms such as 'validation,' 'prototype,' and 'startup,' which are common in normal conversation and across many unrelated skills. This makes accidental or excessive invocation likely, creating prompt-routing confusion and increasing the attack surface for misuse or unintended behavior.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger keywords are broad terms like "validation," "prototype," "saas," and "startup," which can match many ordinary user requests and cause this skill to activate outside its intended niche. Over-broad activation increases the chance of prompt-routing errors, where a generic conversation is steered into this workflow unnecessarily, reducing reliability and potentially overriding more appropriate skills or guardrails.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The invocation description covers a very wide set of business and product-related requests without clearly defining exclusions or decision boundaries. This ambiguity can cause accidental invocation for common planning or operations tasks, creating misrouting risk and making downstream behavior less predictable.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The default prompt uses a very broad trigger phrase tied to common business, product, and workflow requests, which increases the chance of unintended or over-eager invocation. Combined with allow_implicit_invocation: true, ordinary user queries about product ideas or planning could activate this skill without clear user intent, causing prompt-context injection into unrelated conversations or unintended data exposure to the skill.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger sentence 'Help me Founders and builders need...' is overly broad and begins with extremely common conversational language, which risks activating the skill for unrelated user requests. In an agent-routing system, broad triggers can cause mis-selection of this skill, leading to inappropriate handling of user intent, prompt-space interference, or denial of access to a more suitable skill.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The phrase 'I need a practical workflow for...' is ambiguous because it lacks clear constraints on topic and could match many benign requests unrelated to startup/product validation. This ambiguity increases the chance of accidental invocation, which can degrade routing integrity and expose users to irrelevant or misleading outputs from the wrong skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.