Back to skill

Security audit

Product Validation Planner

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-only product validation helper with broad activation wording but no hidden code, credential access, persistence, or unsafe actions.

Before installing, be aware that this skill may activate for broad product, startup, validation, prototype, or SaaS requests. That can be mildly annoying or steer answers toward product-validation workflows, but the inspected package does not show unsafe execution or data access behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentence begins with a very generic help-seeking phrase and then embeds the full requirement text, making activation conditions overly broad and likely to match ordinary user requests that are only loosely related. This can cause unintended invocation of the skill, leading to prompt-routing confusion, inappropriate responses, or overshadowing of more suitable skills.

Vague Triggers

Medium
Confidence
87% confidence
Finding
This trigger sentence is ambiguous because 'I need a practical workflow for...' is a common phrase that could apply to many domains, while the appended requirement text is truncated and not a precise task description. In a multi-skill environment, ambiguous triggers increase the chance of accidental activation and misclassification of user intent.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are generic enough to match ordinary product, startup, and workflow requests, which can cause the skill to activate when the user did not explicitly intend to use it. This creates a scope-control problem: the agent may be steered into this skill too often, overriding more appropriate behavior or causing unintended disclosure of user context into the skill workflow.

Vague Triggers

High
Confidence
94% confidence
Finding
The skill description is broad enough to match many ordinary product, startup, and business-support requests without clear boundaries or exclusion criteria. In an agent system, this can cause over-invocation, routing conflicts, and unintended handling of user requests by a skill that was not specifically intended, which increases the chance of inappropriate actions or leakage of context into the wrong workflow.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger keywords and example phrases are generic terms like 'validation,' 'prototype,' 'saas,' and 'startup,' which commonly appear in unrelated requests. Because there are no specificity checks or negative conditions, the skill may activate for a wide range of conversations, leading to skill hijacking, poor task routing, and potentially exposing broader conversation context to an unnecessarily invoked skill.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger keywords are generic terms like 'product idea', 'validation', 'prototype', 'saas', and 'startup', which commonly appear in many normal conversations. This can cause the skill to activate outside its intended scope, leading to inappropriate routing, over-application of the workflow, or overshadowing more suitable skills. In agent systems, broad activation increases the attack surface for prompt steering and misclassification.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description says to use the skill when users ask for broad categories such as business-and-operations, product idea, validation, prototype, or saas, but it does not clearly define exclusion criteria or decision boundaries. This ambiguity can lead to accidental invocation on loosely related requests, causing incorrect task routing and increasing the chance that the agent follows an irrelevant workflow instead of the safest or most appropriate one.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables allow_implicit_invocation without any visible bounded trigger phrase, narrow scope, or additional guardrails. This can cause the agent to auto-select the skill in loosely related conversations, increasing the chance of unintended prompt injection exposure, inappropriate business guidance, or execution in contexts the user did not explicitly request.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger phrases are overly generic and match broad, everyday requests such as asking for a 'practical workflow' around common business topics. This can cause the skill to activate unintentionally in unrelated contexts, leading to prompt-routing confusion, unexpected behavior, and possible interception of user requests that should be handled by a more appropriate skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.