Back to skill

Security audit

Product Validation Planner

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only planning skill for product-validation help, with overly broad activation wording but no evidence of hidden execution, persistence, credential access, or data exfiltration.

Before installing, be aware that the skill may activate for generic product-related wording because its triggers are broad and implicit invocation is enabled. It is otherwise a low-risk, text-only planning aid; narrowing the triggers would make routing cleaner.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description includes very broad trigger terms like "ask," "product," and "very," which can match a wide range of unrelated requests and cause the skill to activate outside its intended scope. Overbroad activation can route benign user tasks into the wrong workflow, increasing the chance of irrelevant guidance, prompt interference, or unintended handling of user data/context.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The explicit keyword list contains highly ambiguous common words such as "ask," "product," "very," "high," and "ready," which are likely to appear in ordinary conversations unrelated to this skill. In an agent system, this can cause frequent false-positive invocation and unintended priority over more appropriate skills, degrading control over routing and making prompt-scope abuse easier.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger keywords include very broad terms such as "ask", "product", and "very", which are common in normal user conversations and can cause the skill to activate unintentionally. Over-broad activation can route unrelated requests into this skill, producing irrelevant guidance, confusing users, and interfering with safer or more appropriate skill selection.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger sentences are broad and unnatural enough to match loosely related user requests, which can cause the skill to activate outside its intended scope. In an agent environment, overbroad activation can route user input into the wrong workflow, producing irrelevant guidance or bypassing more appropriate skills, though this README alone does not indicate direct code execution or data exfiltration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented trigger keywords and phrases are broad and weakly scoped, including generic terms like "ask," "product," and "very," which can cause the skill to activate in unrelated conversations. This creates a prompt-routing vulnerability where users may be unintentionally steered into this workflow, leading to irrelevant guidance, confusion, or accidental disclosure of context to the wrong skill path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

该文件整体为 zh-CN 语言版本,但正文未说明这是可选语言呈现,也未给出用户语言选择或切换方式。若技能默认强制以简体中文面向所有用户,可能构成未获用户同意的语言/地区策略限制。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation section defines keywords and sample invocations but does not provide clear boundaries, exclusions, or disambiguation rules. Without guardrails, the system may invoke the skill for loosely related prompts, increasing the chance of prompt routing errors, poor task handling, and accidental override of more suitable skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The default prompt and description use broad, everyday phrasing such as 'Help for a Product,' which can match many ordinary user requests and cause the skill to be invoked unintentionally. Overbroad invocation text increases the chance that the agent routes unrelated conversations into this skill, potentially exposing user context unnecessarily and creating unsafe or confusing behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Enabling implicit invocation without meaningful trigger constraints allows the platform to auto-select this skill based on weak semantic matches. In combination with the vague skill description, this can cause frequent accidental activation, misrouting user requests and broadening the skill's access to conversation context beyond what is necessary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases and keywords are broad enough to match many ordinary requests, such as generic mentions of 'help', 'product', 'ask', or 'workflow'. This can cause unintended invocation of the skill in unrelated contexts, leading to incorrect routing, over-collection of user context, or generation of outputs under the wrong workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This file is presented as a Chinese README, but key user-facing content such as the need statement, target users, and workflow description remains in English. That can create an implicit language-policy issue because the skill does not state whether users may choose their preferred language or that mixed-language output is intentional.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.