Back to skill

Security audit

Product Validation Planner

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only product validation planning skill with broad activation wording but no hidden code, install steps, data access, persistence, or privileged behavior.

Before installing, note that the skill may activate on broad startup, SaaS, prototype, or validation wording. It appears safe from a security standpoint, but users who want precise routing may prefer narrower trigger phrases or explicit invocation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are broad, generic requests such as 'Help me' and 'I need a practical workflow', which can cause the skill to activate in contexts beyond product validation. Over-broad activation increases the chance of unintended routing, prompt hijacking of normal conversations into this skill, or inappropriate use on unrelated tasks where its instructions may override better-matched safeguards.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad generic help-seeking prompts such as asking for a practical workflow or help with product validation, which can cause the skill to activate in situations far beyond its intended scope. In an agent environment, this increases the chance of inappropriate routing, prompt shadowing, or the skill taking over unrelated user requests, which can degrade safety controls and produce misleading outputs.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger keywords are broad and generic terms like 'validation', 'prototype', 'saas', and 'startup', which can match many routine requests outside the skill's intended scope. This increases the chance of unintended activation, causing the agent to inject irrelevant planning behavior into unrelated conversations and potentially override more appropriate skills or system behavior.

Vague Triggers

High
Confidence
94% confidence
Finding
The manifest description defines activation for a very wide range of requests, including broad domains like business operations, product ideas, validation, prototypes, SaaS, and general implementation support. Such ambiguity can make the skill eligible for many unrelated prompts, leading to over-selection, prompt-scope drift, and reduced reliability of the agent's routing decisions.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill description and activation guidance are broad enough that ordinary product, business, validation, or startup conversations could trigger it unintentionally. Over-broad triggering can route users into a prescriptive workflow they did not request, causing inappropriate tool selection, context confusion, and possible downstream misuse of any higher-privilege capabilities exposed through the skill system.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The keyword list includes generic terms such as business-and-operations, validation, prototype, saas, and startup without contextual qualifiers. These broad keywords increase false activations, which is risky because the agent may switch into a specialized planning mode for unrelated requests and expose users to unintended actions or recommendations.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt embeds a broad natural-language invocation phrase ('Use $product-validation-planner to help me...') without meaningful trigger constraints, which can cause the skill to be invoked in contexts beyond the user's actual intent. Because implicit invocation is also enabled, this increases the chance of over-broad routing, prompt confusion, or unintended use of the skill when users mention adjacent business or product topics.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentences are generic and map to broad business/product language, which increases the chance the skill is invoked for loosely related requests rather than clear, user-intended use. In an agent system, overbroad activation can cause incorrect tool selection, unexpected disclosure of internal planning behavior, or unnecessary execution of a skill in contexts where it is not the best fit.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.