Back to skill

Security audit

Product Validation Planner

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only product validation planning skill with some broad activation wording but no hidden execution, credential access, persistence, or destructive behavior.

This skill appears safe to install for product idea validation and startup planning. Be aware that its broad triggers may activate for general product, SaaS, startup, prototype, or validation conversations, so users who prefer tighter routing should invoke it explicitly or adjust invocation settings if available.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentence is extremely broad and can match ordinary user requests for general help, which risks activating this skill outside its intended scope. Over-broad activation can cause skill hijacking or unintended prioritization over more appropriate skills, leading to confused behavior and unsafe routing decisions.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The invocation description is ambiguous because it allows activation for vague requests like needing a 'practical workflow' without sufficiently constraining the topic or task. In a multi-skill agent, this increases the chance of accidental or excessive invocation, which can degrade routing integrity and cause the skill to handle requests beyond its designed business-validation context.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad enough to match very common requests like asking for a practical workflow or help with a product idea, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of inappropriate routing, prompt collisions with other skills, and accidental use in contexts where the user did not explicitly want this planner.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description is broadly scoped to common product, business, and prototype requests, so it can be invoked for many unrelated conversations where a more specific skill would be safer or more appropriate. Over-broad activation increases the chance of unintended routing, causing users to receive irrelevant guidance, bypass more specialized controls, or expose additional context to a skill that was not necessary.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The keyword triggers include very generic terms such as 'validation', 'prototype', 'saas', and 'startup', which are common across many benign and unrelated requests. Without scope constraints, these triggers can cause accidental invocation and misrouting, reducing reliability and potentially surfacing this skill in contexts where different safety, privacy, or domain-specific handling is needed.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger keywords and example invocations are broad enough to match many ordinary product or startup conversations, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of unintended instruction injection into unrelated tasks and can override more appropriate skills or baseline behavior.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The manifest description defines activation in very general terms such as business operations, product ideas, validation, prototypes, and implementation support, without clear scope limits. This ambiguity can lead to accidental activation on a wide range of benign requests, increasing the attack surface for prompt steering and causing the assistant to apply this skill where it is not appropriate.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt trigger is overly broad and overlaps with common business/product assistance requests, which increases the chance of unintended or implicit invocation. Because implicit invocation is enabled, normal user language about product ideas, validation, prototypes, or workflows could activate this skill without clear user intent, causing prompt injection surface expansion and unexpected data flow into the skill.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentence begins with a broad everyday phrase ('Help me') and then maps into a wide business/product workflow skill. This can cause unintended activation on many ordinary user requests, increasing the chance the agent invokes this skill outside its intended scope and routes users into a workflow they did not ask for.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The phrase 'I need a practical workflow for ...' is vague and lacks clear boundaries on when the skill should activate. Because the skill targets a broad business-and-operations category, ambiguous wording can lead to over-triggering and inappropriate capture of unrelated requests, which is a prompt-routing/control weakness.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.