Back to skill

Security audit

Product Validation Planner

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only product validation planning skill with broad activation wording but no hidden actions, credential use, persistence, or destructive behavior.

Installers should expect this skill to influence product-validation and startup-planning conversations, and should consider narrowing its triggers if they want fewer accidental activations. No evidence was found that it performs actions outside normal advisory planning behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentence is extremely broad and maps to generic user requests like 'help me' or 'I need a practical workflow,' which can cause the skill to activate outside its intended product-validation scope. Over-broad activation increases the chance of incorrect routing, prompt collisions with other skills, and unintended exposure of this skill's instructions in unrelated contexts.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The invocation guidance lacks precise boundaries for when the skill should and should not run, making it easy for common business or planning requests to match accidentally. In an agent environment, this kind of ambiguity can lead to unauthorized or unintended skill invocation, reducing reliability and creating opportunities for prompt-surface abuse through broad routing.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are broad and partially generic, which can cause the skill to activate for loosely related requests rather than explicit user intent. In an agent system, unintended invocation can route user data or task flow into the wrong skill, reducing reliability and potentially causing inappropriate business guidance or context leakage across workflows.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description is very broad and targets generic business, product, validation, prototype, and SaaS requests, which increases the chance the agent invokes this skill for loosely related prompts. Overbroad routing can cause unintended tool selection, reducing least-privilege behavior and potentially displacing safer or more appropriate skills.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The keyword triggers and example phrases are ambiguous, short, and common across many benign conversations, making accidental activation likely. In an agentic environment, ambiguous triggers can lead to prompt-routing errors, scope creep, and inappropriate access to this skill's instructions when another workflow should have handled the request.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords are broad, generic terms such as 'validation', 'prototype', 'saas', and 'startup', which can match many unrelated user requests and cause the skill to be invoked unexpectedly. Over-broad activation can steer conversations into this skill's workflow when the user did not intend it, leading to misrouting, irrelevant guidance, and reduced trust in agent behavior.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description says it should be used for broad categories like business-and-operations, product idea, validation, prototype, and saas, without clear boundaries or exclusion conditions. This makes the routing surface excessively large, increasing the chance of accidental invocation and inappropriate application of the skill to requests outside its intended domain.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt uses a very broad trigger phrase tied to common business and product-related requests, which can cause the skill to be invoked in situations beyond the user's clear intent. Combined with allow_implicit_invocation: true, this increases the chance of inappropriate routing, over-collection of context, or unintended influence over unrelated conversations.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentence is broad enough to match ordinary user phrasing about help, workflows, or product ideas, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of incorrect routing, prompt shadowing, or untrusted skill invocation when a more appropriate skill or default handling should have been used.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The usage signals section lacks clear activation boundaries and relies on very general keywords such as 'business-and-operations', 'product idea', 'validation', and 'startup', which overlap heavily with normal conversation. This makes accidental or overly aggressive invocation likely, potentially steering unrelated requests into this skill and degrading safety, predictability, and least-privilege routing.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.