Back to skill

Security audit

Product Validation Planner

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only planning skill for product-validation help, with no code execution or data access, though its activation wording is overly broad.

Install only if you want a lightweight product-validation planning assistant. Be aware it may activate on broad product/help wording, so explicit invocation or narrower trigger wording would reduce accidental use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill metadata description includes very broad activation terms like 'creative-and-content', 'ask', 'product', and 'very', which are generic enough to match many unrelated user requests. Over-broad routing can cause unintended invocation of this skill, leading to incorrect handling, prompt/context pollution, or accidental exposure of internal workflow instructions in contexts where the skill is not appropriate.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The listed trigger keywords include extremely generic words such as 'ask', 'product', 'very', 'high', 'quality', and 'ready', which can match a large fraction of normal conversations. This makes accidental invocation highly likely and can systematically misroute user requests to this skill, degrading safety and reliability across the agent by applying the wrong instructions in unrelated contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example trigger phrases are vague and circular, for example 'Help me Help for a Product', and do not meaningfully constrain when the skill should run. Ambiguous examples reinforce permissive matching behavior and make it harder for maintainers or routing systems to distinguish valid invocations from incidental language overlap.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The default prompt uses a very broad phrase, "Help for a Product," which can match ordinary user language rather than a narrow, intentional trigger. This increases the chance of unintended skill invocation, causing the agent to apply this skill in contexts the user did not explicitly request and potentially overriding more appropriate behavior or exposing the user to unintended automated planning output.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Enabling implicit invocation without clear trigger boundaries allows the platform to activate this skill based on loose semantic similarity instead of explicit user intent. In combination with the generic product-help description, this can lead to overbroad routing, accidental activation across normal conversations, and unpredictable application of the skill in unrelated contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases and keywords are broad enough to match many ordinary product/help requests, which can cause this skill to activate outside its intended scope. Overbroad activation is dangerous because it can route unrelated user requests into the wrong workflow, producing irrelevant guidance and increasing the chance of unintended handling of sensitive or higher-risk tasks.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.