Back to skill

Security audit

Product Validation Planner

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable planning skill for product idea validation, with broad activation wording but no hidden code, credentials use, persistence, or destructive behavior.

Before installing, be aware that this skill may activate on broad product, SaaS, startup, or validation requests. Its behavior is limited to planning and artifact generation, so the main practical risk is irrelevant guidance rather than unsafe system access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are so generic that they can match ordinary product, startup, or workflow requests that were not intended to invoke this skill. Overbroad activation can cause inappropriate routing, unexpected behavior, and increased prompt-surface exposure to skill instructions in unrelated conversations, which is a real security and safety concern for agentic systems.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad enough to match many normal business or product conversations, which can cause the skill to activate when the user did not explicitly ask for it. In an agent environment, overbroad activation can steer workflows, inject unsolicited planning behavior, or crowd out more appropriate skills, increasing the chance of unintended actions or misleading outputs.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger keywords are broad, generic product terms such as 'prototype', 'saas', and 'startup', which can cause the skill to activate in many ordinary conversations that do not actually need this workflow. Over-broad activation increases the chance of incorrect routing, unwanted instruction injection into unrelated tasks, and interference with more appropriate skills, even though the content here is not overtly malicious.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The description defines activation in very expansive terms, covering broad domains like business operations, product ideas, prototypes, SaaS, workflows, artifacts, analysis, and implementation support. This ambiguity makes the skill eligible for a wide range of benign user requests, creating prompt-selection risk where the agent may invoke this skill unnecessarily and let its guidance steer conversations outside its intended scope.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill uses very broad trigger keywords such as 'validation', 'prototype', 'saas', and 'startup', which commonly appear in normal conversations. This can cause unintended activation of the skill in contexts where the user did not explicitly request it, leading to inappropriate routing, irrelevant outputs, or overshadowing of more suitable skills.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The default prompt uses a broad, ambiguous invocation phrase that can cause the skill to activate in situations beyond the author's likely intent, especially because implicit invocation is enabled. This increases the chance of unintended routing or prompt influence, which can expose users to irrelevant or potentially unsafe automated behavior without a clear consent boundary.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger phrases and keywords are broad enough to match ordinary requests about business, product ideas, validation, prototypes, or SaaS, which can cause the skill to activate in situations the user did not explicitly intend. Over-broad invocation increases the chance of context hijacking or incorrect tool routing, especially because the skill claims authority over generic workflow and implementation support across a wide range of common requests.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.