Back to skill

Security audit

Product Validation Planner

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only product validation planning skill with broad activation wording but no hidden automation, credential access, persistence, or destructive behavior.

Before installing, be aware that this skill may be selected for broad product, startup, SaaS, validation, or prototype requests. It is suitable for planning help, but users should explicitly name another skill or clarify scope when they need unrelated business advice or technical implementation work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentence starts with very common phrasing ('Help me') and then appends a broad requirement description, making activation boundaries unclear. This can cause accidental invocation in unrelated user conversations, leading the agent to apply this skill when the user did not explicitly intend to use it.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The phrase 'I need a practical workflow for ...' is broad and ambiguous, so normal business-assistance requests could unintentionally match this skill. In an agent environment, overly permissive trigger language increases the chance of misrouting user requests and invoking instructions outside the user's intended context.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are broad and overlap with common user requests such as product ideas, validation, prototypes, and startup help. This can cause accidental or excessive activation of the skill in contexts where the user did not explicitly intend to invoke it, leading to inappropriate handling of requests or routing to the wrong workflow.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The top-level description is very broad and maps to common business, product, and workflow requests, which increases the chance this skill will activate for many unrelated prompts. Over-broad routing can cause unintended skill selection, leading to misleading outputs, instruction precedence issues, or accidental exposure of internal workflow content in contexts where it was not the best match.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The keyword list and example triggers are ambiguous, highly generic, and lack exclusion criteria, making the skill easy to invoke for ordinary requests that only loosely relate to product validation. This broad matching expands the attack surface for prompt-routing abuse and increases the likelihood of the wrong skill being selected, which can degrade safety and reliability of the agent's behavior.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description and usage conditions are broad enough to match many ordinary startup, product, and operations conversations, which can cause over-triggering. Overly broad invocation can route unrelated user requests into this skill, producing irrelevant guidance, suppressing better-matched skills, and increasing the chance of unsafe or low-quality automated actions in the wrong context.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The keyword list is generic and lacks boundary conditions, so common terms like 'prototype', 'validation', 'saas', or 'startup' may activate the skill in many unrelated conversations. In an agent system, this increases unintended execution and context hijacking risk, especially when the skill is allowed to generate workflows, code changes, or decision support without a precise scope check.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill enables allow_implicit_invocation without any visible activation constraints, which can cause the agent to invoke this skill based only on broad topical similarity. Because this skill influences business, product, and operational planning, unintended activation could expose user context to the skill or cause unrequested planning actions, increasing the risk of prompt-scope confusion and inappropriate automation.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence begins with a very broad phrase ('Help me') and then appends the requirement text, which can cause the skill to activate for many ordinary user requests that are not clearly asking for this specific capability. Overbroad activation increases the chance of unintended routing, where this skill may intercept queries outside its intended scope and produce irrelevant or misleading business-planning guidance.

Vague Triggers

Medium
Confidence
88% confidence
Finding
This trigger sentence is ambiguous because 'I need a practical workflow for...' is still generic and does not clearly bound when the skill should activate versus other planning, operations, or documentation skills. Ambiguous activation scope can lead to false-positive invocation, creating prompt-routing confusion and reducing trust in the agent's skill selection behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.