Back to skill

Security audit

Product Validation Planner

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only product validation planning skill with broad activation wording, but it does not request sensitive access, persistence, or destructive authority.

Installers should know this skill may be invoked for fairly broad product, startup, validation, or prototype requests. It appears safe as a planning aid, but users who run many overlapping business skills may want narrower trigger wording to avoid accidental activation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence is broad enough to match ordinary user phrasing about needing help or a workflow, which can cause the skill to activate outside its intended scope. Overbroad activation increases the chance of prompt/context hijacking at the routing layer, where a business-planning skill may intercept unrelated requests and influence outputs unexpectedly.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The invocation guidance does not define clear boundaries for when the skill should and should not run, and the listed keywords are common across many benign conversations. This ambiguity can lead to accidental invocation, inappropriate tool selection, and unintended influence over responses in contexts unrelated to product validation.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrase is broad enough to match common user language about needing a practical workflow, which can cause this skill to activate in situations beyond its intended scope. Overbroad activation increases the chance of accidental routing, context leakage into the wrong skill, and unsafe or irrelevant guidance being presented to users.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is broad enough to match many ordinary business, product, and operations requests, which can cause the agent to invoke this skill outside its intended scope. Over-broad routing increases the chance of inappropriate tool/skill selection, leading to irrelevant guidance, prompt-surface expansion, and possible interference with more suitable specialized skills.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The keyword triggers and example invocations use highly generic terms such as 'validation', 'prototype', 'saas', and 'startup', which are common across many unrelated requests. This makes accidental or overly frequent activation likely, reducing routing precision and potentially exposing users to the wrong workflow or causing conflicts with other skills in the environment.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger section uses very broad keywords such as "validation", "prototype", "saas", and "startup", which can match many ordinary product or business requests without clear boundaries. This can cause the skill to activate in unintended contexts, overriding more appropriate skills or steering the agent into a workflow the user did not ask for, which is a prompt-scope and behavior-control issue rather than direct code execution.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The skill content is entirely in Chinese and does not state that language should follow the user's preference or locale. In a mixed-language environment, this can cause the agent to respond in an unexpected language, reducing user comprehension and potentially causing misunderstanding of business, planning, or implementation guidance.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The default prompt invokes the skill using a very broad, generic phrase tied to common business and product-related requests, which can cause the agent to activate in situations where the user did not explicitly intend to use this skill. Because implicit invocation is also enabled, this increases the chance of over-triggering, prompt routing mistakes, and unintended exposure of user context to the skill.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger phrases are generic and overlap heavily with ordinary product, startup, and workflow requests, making accidental invocation likely. In an agent-routing system, this can cause the skill to activate outside its intended scope, steering users into this workflow when they asked for more general help and potentially overriding better-matched or safer skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.