Back to skill

Security audit

Product Validation Planner

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk planning skill for product idea validation, with broad activation wording but no code, persistence, credential access, or hidden behavior.

Installers should be aware this skill may be selected for broad product or startup-related requests. It is appropriate for product validation planning, but trigger wording should ideally be narrowed if the user wants stricter routing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentence is written as a generic help request rather than a narrowly scoped invocation, which increases the chance the skill activates during ordinary conversation. In an agent environment, unintended activation can route user input into the wrong workflow, causing irrelevant business-planning behavior, confusion, or accidental processing of sensitive context not meant for this skill.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The invocation guidance is broad and underspecified, with keywords like 'validation', 'prototype', 'saas', and 'startup' covering many normal user requests. This makes over-triggering more likely, which is dangerous because the skill may intercept unrelated tasks and steer outputs based on its own workflow rather than the user's actual intent.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad, generic, and include common terms like product idea, validation, prototype, and practical workflow, which can cause the skill to activate for many ordinary user requests beyond its intended scope. This increases the chance of unintended routing, priority hijacking, or inappropriate invocation of the skill when another, more suitable skill or default behavior should handle the request.

Vague Triggers

High
Confidence
94% confidence
Finding
The skill description uses very broad activation terms such as business-and-operations, product idea, validation, prototype, saas, and practical workflow support, which can match a large range of normal user requests. This can cause the skill to be invoked outside its intended scope, leading to prompt hijacking of unrelated tasks, degraded routing quality, or accidental exposure of the skill's instructions in contexts where it does not belong.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger keywords and example trigger sentences are generic and unconstrained, making it likely that common startup or product-related queries will activate the skill even when the user did not intend to use it. Overbroad triggering increases the chance of incorrect tool selection, instruction interference, and reduced reliability of the agent's behavior across unrelated conversations.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger section uses broad, common keywords such as 'validation', 'prototype', 'saas', and 'startup', which can match many unrelated user requests. This increases the chance the skill is invoked outside its intended scope, causing response hijacking, misrouting, or inappropriate workflow application in contexts where another skill should handle the request.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The top-level description defines the skill's usage scope very broadly across business operations, product ideas, validation, prototypes, SaaS, and any request for workflows, artifacts, analysis, or implementation support. Because these categories overlap heavily with many legitimate assistant tasks, the skill may over-claim relevance and be selected when it is not the best or safest fit.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt invokes the skill using a very broad phrase tied to generic business, product, and workflow requests, which can cause the agent to activate in contexts beyond the user's clear intent. Combined with implicit invocation, this increases the risk of unintended routing, over-collection of user context, or inappropriate use of the skill when a narrower tool would be safer or more accurate.

Vague Triggers

High
Confidence
90% confidence
Finding
The trigger sentence is overly broad and can cause the skill to activate on common product-related requests that do not specifically require this workflow. Over-broad activation increases the chance of inappropriate routing, where the agent applies this skill in contexts it was not intended for, potentially crowding out safer or more relevant skills and producing misleading business guidance.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation guidance is ambiguous because it mixes broad keywords with truncated, repetitive trigger phrases and lacks precise boundaries for when the skill should or should not run. In a multi-skill agent, this can lead to misrouting and over-selection of this skill for loosely related business requests, reducing reliability and potentially causing users to receive irrelevant planning advice instead of the correct capability.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.