Back to skill

Security audit

Product Validation Planner

Security checks across malware telemetry and agentic risk

Overview

The skill is a documentation-only product-validation planning helper; its triggers are broad, but it does not request credentials, code execution, persistence, or sensitive access.

Before installing, be aware that this skill may be invoked for loosely related product, startup, validation, prototype, or SaaS requests. It appears safe as a planning aid, but users should not treat its demand score or linked evidence as independently verified market research without checking the sources themselves.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentences are broad and partially generic, so the skill may be invoked for loosely related requests instead of only clear product-validation tasks. In an agent environment, ambiguous routing can cause unintended activation, leading to irrelevant guidance, context bleed, or accidental influence over workflows that the user did not intend this skill to control.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad and loosely scoped, using generic terms like 'validation', 'prototype', and 'saas' that could cause the skill to activate for unrelated requests. In an agent system, ambiguous activation can route users into the wrong workflow, override more appropriate skills, or cause unintended handling of sensitive business requests.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description and usage guidance are broad enough to match many ordinary product, startup, or planning requests, which increases the chance of unintended invocation. Overbroad activation can route users into a specialized workflow they did not request, causing prompt-scope confusion, reduced reliability, and possible interference with safer or more relevant skills.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger keywords are generic business terms like 'validation,' 'prototype,' and 'startup,' which commonly appear in unrelated conversations. This makes accidental activation likely and weakens control over when the skill should run, potentially overshadowing better-matched skills or altering the assistant's behavior unexpectedly.

Vague Triggers

Low
Confidence
89% confidence
Finding
The example trigger sentences use everyday phrasing that lacks boundaries and effectively teaches the system to activate on vague product-help requests. While not directly harmful code or data exfiltration logic, this broad matching behavior can still cause misrouting and prompt selection errors in routine use.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger keywords are broad enough to match many ordinary product or startup discussions, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of inappropriate routing, unnecessary instruction injection from the skill, or the model prioritizing this workflow when a more suitable skill or direct answer should be used.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The invocation guidance says to use the skill whenever users need practical support around a very broad requirement statement, which makes scope boundaries unclear. Ambiguous routing criteria can lead to accidental invocation in loosely related business conversations, reducing predictability and potentially exposing users to irrelevant or conflicting workflow instructions.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt uses a very broad, natural-language invocation phrase that can match many ordinary product, business, or prototype-related requests without clear boundaries. Combined with allow_implicit_invocation: true, this increases the chance the skill is auto-invoked in contexts the user did not explicitly intend, which can cause overreach, prompt-routing mistakes, or unintended access to the skill’s guidance in adjacent conversations.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentences are broad, awkwardly templated, and overlap with common user requests about product ideas, workflows, validation, prototypes, and SaaS. This can cause the skill to activate in unintended contexts, leading to misrouting, prompt collisions with other skills, or inappropriate injection of this workflow into unrelated conversations; while not a direct code-execution flaw, it is a genuine security/control-plane issue in agent orchestration.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.