Back to skill

Security audit

Product Validation Planner

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only planning skill for product idea validation, with no executable code or hidden high-impact behavior found.

This skill appears safe to install for product-validation planning, but users should expect it may activate on broad startup, SaaS, prototype, or validation requests. Tightening trigger wording would improve routing precision.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentence is broad and generic enough to match ordinary product or business-help requests, which can cause the skill to activate outside its intended scope. In an agent system, overbroad activation increases the chance of unintended instruction injection into unrelated conversations and can degrade routing safety and predictability.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The invocation guidance lacks precise boundaries and mostly repeats requirement text instead of defining when the skill should or should not be used. This ambiguity can cause accidental selection of the skill for loosely related prompts, expanding the attack surface for prompt-confusion or misrouting in multi-skill environments.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are very broad and map to common business/product requests, which increases the chance this skill will be invoked unintentionally for ordinary conversations. Over-broad activation can route users into a specialized workflow they did not ask for, causing inappropriate context capture, misleading outputs, or unnecessary tool behavior across a wide range of benign prompts.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description casts a very wide net across common business and product-assistance requests, making accidental or unnecessary invocation likely. Over-broad routing can cause the wrong skill to handle unrelated user requests, which may bypass more appropriate constraints or lead to lower-quality, mis-scoped outputs at scale.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords are highly generic terms commonly appearing in ordinary user prompts, so this skill may activate in situations far outside its intended scope. In multi-skill environments, such ambiguous triggers increase prompt-routing errors and can cause unintended tool selection, creating reliability and policy-boundary risks.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description and activation scope are broad enough to match many common business/product requests, which increases the chance the agent invokes this skill in situations where a narrower or more appropriate skill should apply. Overbroad routing can cause unintended execution paths, irrelevant guidance, or unsafe task blending if downstream skills have different trust or action boundaries.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The keyword list contains generic terms like 'validation', 'prototype', 'saas', and 'startup' without disambiguation or negative examples, making accidental or overly aggressive triggering likely. This can let the skill intercept unrelated user requests, reducing routing precision and potentially bypassing more context-appropriate safeguards or workflows.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt uses a very broad invocation phrase tied to a wide set of business/product requests, which increases the chance of unintended or automatic activation outside a narrowly scoped user intent. Because implicit invocation is enabled, this broad trigger can cause the skill to engage in contexts where it was not specifically requested, leading to prompt-scope overreach, confusing behavior, or unintended exposure of the skill's instructions and capabilities.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger phrases are highly generic and include broad business/product terms that can match many ordinary user requests, which increases the chance this skill is invoked when another skill would be more appropriate. In agent systems, overbroad invocation can cause routing errors, accidental context capture, and unintended execution paths even when the skill itself is not overtly malicious.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.