Back to skill

Security audit

Product Validation Planner

Security checks across malware telemetry and agentic risk

Overview

This is an advisory product-validation planning skill with broad activation terms but no executable code, persistence, credential use, or hidden data movement.

Installers should know this skill may activate on broad product or startup-related requests. It appears safe as a planning aid, but users who want tighter control should invoke it explicitly or narrow its trigger language before broad deployment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger sentences are broad enough that the skill may activate for loosely related requests, causing unintended routing or overuse of this skill when a more appropriate tool should handle the task. In an agent ecosystem, ambiguous activation increases the chance of misclassification, confusing outputs, and accidental execution of business-planning guidance in contexts the user did not intend.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad enough to match many ordinary product, startup, and workflow requests, which can cause this skill to activate when the user did not specifically intend to use it. Over-broad activation increases the chance of inappropriate routing, prompt hijacking of general conversations into this skill, and reduced user control over which capability is invoked.

Vague Triggers

High
Confidence
94% confidence
Finding
The skill description is broad enough to match many ordinary product, startup, and operations requests, which can cause the agent to invoke this skill outside its intended niche. Over-broad routing increases the chance of inappropriate tool selection, irrelevant guidance, or interference with more specific skills, especially in automated orchestration environments.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger keywords are generic terms like 'validation', 'prototype', and 'startup', which are ambiguous across many domains and likely to produce accidental activation. In a skill-routing system, vague triggers can lead to prompt hijacking-by-selection, where the wrong skill gains influence over the conversation simply because its match criteria are too loose.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger keywords are broad and generic (e.g., 'validation', 'prototype', 'saas', 'startup'), which can cause the skill to activate during ordinary product discussions outside its intended scope. This increases the chance of unintended routing, context hijacking, or overshadowing more appropriate skills, leading to confused outputs or policy bypass in multi-skill environments.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The invocation description says to use the skill for broad categories like business operations, product ideas, validation, prototypes, and SaaS without clearly limiting boundaries. Ambiguous activation criteria can cause over-invocation and misclassification of user intent, which is especially risky in agent systems where the wrong skill may shape the entire response path.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables implicit invocation (`allow_implicit_invocation: true`) without any visible constraints on when it should activate or when it should be excluded. This can cause the agent to invoke the skill on loosely related product, business, or validation requests, increasing the chance of unintended prompt routing, over-collection of user context, or unsafe delegation based on ambiguous user intent.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentence starts with a broad, conversational phrase ('Help me ...'), which can cause the skill to activate for many ordinary user requests that are only loosely related to product validation. Over-broad activation boundaries increase the chance of unintended routing, where users are pushed into this workflow when they intended a different skill or a general response, creating confused-deputy style behavior at the orchestration layer.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The phrase 'I need a practical workflow for ...' is ambiguous and broad enough to match many unrelated planning or operational requests, without clear constraints on domain or task type. In a skill-routing system, this can lead to accidental invocation and misclassification of user intent, reducing reliability and potentially exposing users to irrelevant or unsafe guidance if the wrong skill takes control.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.