Back to skill

Security audit

Product Validation Planner

Security checks across malware telemetry and agentic risk

Overview

This skill provides product-validation planning guidance and does not request unusual access, run code, persist in the environment, or handle sensitive data.

Before installing, be aware that this skill may be selected for broad product, startup, SaaS, prototype, or validation requests. That is a routing quality issue to watch, but the inspected artifacts do not show hidden commands, credential handling, persistence, or data exfiltration.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentence is broad and generic enough that it could activate the skill for loosely related user requests, causing inappropriate routing or overuse of the skill outside its intended scope. In an agent system, ambiguous activation criteria can lead to incorrect handling of business, product, or startup queries and reduce trust in tool selection behavior.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation guidance does not clearly specify scope boundaries, so the skill may be invoked for a wide range of adjacent requests based only on broad keywords like 'business-and-operations' or 'prototype.' This is dangerous because overbroad routing in agent skills can misclassify user intent, crowd out more appropriate skills, and create unreliable or unexpected automated behavior.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger phrases are broad enough to match common business, product, and startup-related requests, which can cause the skill to activate when the user did not explicitly intend to use it. Over-broad invocation increases the risk of prompt-routing mistakes, inappropriate capability use, and user confusion, especially in multi-skill environments where ambiguous routing can expose unintended instructions or behavior.

Vague Triggers

High
Confidence
95% confidence
Finding
The skill description is broad enough to activate on many common business, product, and implementation requests, which increases the chance of incorrect routing and unintended invocation. While not directly enabling code execution or data exfiltration, overbroad dispatch can cause the agent to apply the wrong workflow, mishandle user intent, or expose users to inappropriate actions under an ill-fitting skill.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The keyword list uses highly generic terms like 'validation', 'prototype', 'saas', and 'startup' without disambiguation, making accidental matches likely across many unrelated requests. In an agent system, this can degrade routing integrity and cause this skill to override more appropriate, narrower skills.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases are written in broad, everyday language and effectively demonstrate invocation on vague requests rather than constrained scenarios. This reinforces permissive matching behavior and makes the skill more likely to be selected for requests outside its intended validation-planning scope.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description and activation scope include very broad business/product terms that can match many ordinary user requests unrelated to this specific skill. Over-broad routing increases the chance of accidental invocation, causing prompt/context injection into unrelated conversations and potentially displacing more appropriate skills or safeguards.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The keyword list under '触发方式' is overly generic and lacks contextual constraints, so common terms like 'validation', 'prototype', or 'startup' may spuriously activate the skill. In an agent ecosystem, this can lead to incorrect tool selection, unnecessary exposure of skill instructions, and reduced reliability of security-sensitive routing decisions.

Vague Triggers

Low
Confidence
88% confidence
Finding
The example trigger phrases begin with highly common expressions such as 'Help me' and 'I need a practical workflow for', which are structurally similar to everyday user prompts. This makes accidental matching more likely, especially if a dispatcher uses fuzzy or semantic matching rather than exact invocation syntax.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The default prompt uses a broad, ambiguous invocation phrase ('Use $product-validation-planner to help me ...') without clear trigger boundaries or scoped conditions. Combined with allow_implicit_invocation=true, this can cause the skill to activate in unintended contexts, increasing the chance of over-broad routing, prompt hijacking through user phrasing, or accidental use when the user did not explicitly request this capability.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentences are broad, generic, and closely resemble ordinary product-help requests, which can cause the skill to activate in situations far beyond its intended scope. Overbroad activation increases the chance of unintended routing, prompt hijacking of normal conversations into this skill, and reduced user control over whether specialized planning behavior is applied.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.