Back to skill

Security audit

Product Validation Planner

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only product validation planning skill with broad activation wording but no hidden execution, data access, persistence, or credential handling.

Before installing, be aware that this skill may activate on broad product, validation, prototype, SaaS, or startup prompts. It appears safe for planning support, but users should confirm it is the right skill when they need specialized legal, financial, security, or implementation advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentences are broad, repetitive, and loosely scoped, which can cause the skill to activate for vague business or product-related prompts that were not intended to invoke it. Overbroad activation increases the chance of misrouting user requests, bypassing more appropriate skills, or allowing prompt-injection-style content to be funneled into this skill more often than necessary.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger phrases are broad and include generic terms such as product idea, validation, prototype, and startup, which can cause the skill to activate outside its intended scope. In an agent environment, ambiguous activation increases the chance of misrouting user requests, unintended tool invocation, and prompt-surface expansion, though this file does not by itself expose a direct code-execution or data-exfiltration path.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description uses very broad activation terms like business-and-operations, product idea, validation, prototype, and implementation support, which can match many unrelated requests. This can cause the orchestrator to invoke the skill outside its intended niche, leading to scope hijacking, poor routing, and inappropriate instructions being applied to user tasks.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords are generic and cross-domain, especially terms like validation, prototype, and startup, which are common in many unrelated conversations. Overbroad keywords increase accidental activation risk and may let this skill preempt more appropriate specialized skills.

Vague Triggers

Low
Confidence
88% confidence
Finding
The example trigger sentences are written in broad, everyday phrasing and effectively encourage invocation for loosely related requests. This reinforces ambiguous routing behavior and makes it more likely that the skill activates on partial semantic overlap rather than clear intent.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description is broad and includes generic business/product terms, which can cause the router to invoke this skill for many loosely related requests. Over-broad invocation increases the chance that users receive irrelevant guidance, and in a multi-skill environment it can overshadow more appropriate skills or steer workflows in unintended ways.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The keyword trigger list uses very generic terms like product idea, validation, prototype, saas, and startup without qualifiers or negative examples. This makes accidental triggering more likely, which can misroute user requests, reduce system reliability, and potentially suppress safer or more specialized skills.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The default prompt is broadly phrased and maps to a wide set of business, product, and implementation-related requests without clear boundaries or qualification criteria. Combined with implicit invocation, this can cause the skill to trigger in contexts where it was not specifically requested, increasing the chance of unintended delegation, over-collection of user context, or inappropriate influence on planning and operational decisions.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger sentence is excessively broad and can match ordinary user phrasing about help or workflows, causing the skill to activate outside its intended scope. Overbroad activation increases the chance that this skill intercepts unrelated requests, leading to misrouting, unexpected behavior, or prompt-surface expansion where other skills should handle the task.

Vague Triggers

Medium
Confidence
89% confidence
Finding
This trigger pattern relies on a vague request form ('I need a practical workflow for...') without precise scope controls, making activation ambiguous. In a routing system, ambiguous broad triggers can cause incorrect tool selection and allow this skill to be invoked for loosely related business or planning requests, reducing reliability and potentially exposing the agent to unnecessary instruction content.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.