Back to skill

Security audit

Product Validation Planner

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple product-planning prompt package with no executable code, network access, persistence, or credential handling, though its activation wording is overly broad.

Before installing, consider narrowing the trigger keywords or disabling implicit invocation so the skill only activates for explicit product-validation or Ask HN product-help requests. There is no evidence that it runs code, accesses private data, or changes your system.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description uses ambiguous activation guidance such as "Use when a user asks for creative-and-content, ask-hn, ask, product, very" without defining clear boundaries for invocation. In a skill-routing system, vague activation criteria increase the chance of misfires and unintended delegation, which can degrade reliability and expose downstream workflows to irrelevant or sensitive user context.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger keyword list is overly broad and includes common terms like "ask," "product," "very," "high," "quality," and "ready," which are likely to appear in unrelated conversations. This can cause accidental skill activation, routing user requests into the wrong workflow and potentially overriding more appropriate skills or system behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example trigger sentences are too generic and do not clarify what distinguishing context should be present before activation. Because the examples resemble normal user phrasing, they reinforce broad matching behavior and make unintended activation more likely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description and default prompt use highly generic phrasing like 'Help for a Product,' which makes invocation criteria ambiguous and increases the chance the agent will trigger this skill for unrelated requests. Overly broad matching can route user input into an unintended workflow, causing incorrect task handling, prompt-scope confusion, or abuse by attackers who deliberately phrase requests to hijack tool selection.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger scope is overly broad because it includes generic keywords like "ask," "product," "very," and "ready," which can match many unrelated user prompts. This can cause the skill to activate outside its intended context, leading to inappropriate routing, reduced reliability, and possible interception of requests that should be handled by more suitable or safer skills.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.