Back to skill

Security audit

Product Validation Planner

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only planning skill for product idea validation; its triggers are broad, but it does not add code execution, data access, persistence, or privileged behavior.

This skill is reasonable to install if you want help structuring product-idea validation and MVP planning. Be aware that its broad trigger words may make it appear for general startup or product conversations, so users should explicitly choose a more specific skill when they need a different workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger sentence is broad enough to match many ordinary product or startup-related requests, which can cause the skill to activate when the user did not explicitly ask for this workflow. In an agent ecosystem, overbroad activation can hijack routing, override more appropriate skills, and increase the chance of irrelevant or lower-quality outputs.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation guidance provides keywords and trigger sentences but does not define boundaries, prerequisites, or exclusion criteria, so the skill may activate across a wide range of common requests. This weakens routing safety by making invocation ambiguous and easier to trigger unintentionally, which is especially problematic in multi-skill agent environments.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad, generic, and overlap with common product/business requests, which can cause the skill to activate in contexts the user did not explicitly intend. In an agent ecosystem, overly permissive activation increases the chance of misrouting user requests, unexpected tool use, or accidental exposure of this skill's behavior where a narrower match should have been required.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description is broad enough to match many ordinary business, product, and operations requests, which can cause the skill to activate outside its narrowly intended scope. Over-broad routing increases the chance that this skill intercepts unrelated requests, leading to incorrect tool selection, user confusion, or bypass of more appropriate specialized skills.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords such as 'validation', 'prototype', 'saas', and 'startup' are highly generic and likely to appear in many unrelated conversations. This makes accidental invocation more likely, which can misroute requests and reduce the reliability and safety of skill selection in multi-skill environments.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description and activation guidance are broad enough to match many ordinary product, startup, or validation requests, which can cause the agent to invoke this skill when a more appropriate or safer skill should handle the task. Overbroad routing increases the attack surface for prompt collisions, misapplication of instructions, and unintended disclosure or modification in workflows that were not meant to use this skill.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The keyword list contains highly generic terms such as business-and-operations, product idea, validation, prototype, saas, and startup, which are common across many unrelated requests. Generic triggers can cause accidental activation and instruction shadowing, making the agent follow this skill in contexts where its assumptions, workflows, or outputs are inappropriate.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The default prompt invokes the skill with a very broad natural-language trigger covering business, operations, product ideas, validation, prototypes, SaaS, workflows, artifacts, checklists, analysis, and implementation support. Combined with allow_implicit_invocation=true, this increases the chance the skill is auto-selected in loosely related contexts, causing unintended routing, overreach into user tasks, or prompt-surface abuse through ambiguous matching.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is broad enough to match ordinary product-help requests, which can cause the skill to activate outside its intended scope. Overbroad activation increases the chance of prompt routing errors, where this skill intercepts unrelated tasks and injects assumptions, workflows, or business guidance the user did not request.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation examples are ambiguous and fail to clearly define when the skill should and should not be used. In an agent environment, this ambiguity can lead to unintended invocation on common business or product queries, reducing routing precision and potentially causing incorrect task handling.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.