Back to skill

Security audit

Product Validation Planner

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only product validation planning skill with no executable code, credential handling, persistence, or hidden data access.

Installers should know this skill may activate for broad product or startup-related requests; use explicit skill invocation when you want it, and prefer narrower trigger wording in future versions. No evidence of malicious behavior or hidden privileged actions was found.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are broad enough to match many ordinary product, startup, and workflow requests, which can cause the skill to activate when the user did not specifically want this planner. Over-broad activation can override more appropriate skills, distort routing, and increase the chance that business advice is injected into unrelated conversations.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are generic and map to common business/product terms like 'validation', 'prototype', and 'saas', which can cause the skill to activate outside the author's intended scope. In an agent environment, overly broad invocation increases the risk of unintended routing, confusing task selection, and accidental execution of workflows on unrelated user requests.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description is broad enough to match many ordinary product, startup, and operations requests, which increases the chance of unintended invocation. Over-broad activation can route users into the wrong workflow, causing context confusion, inappropriate handling of requests, and possible overshadowing of more suitable or safer skills.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The listed keywords and example triggers are very generic terms like 'validation', 'prototype', 'saas', and 'startup', which are common across many unrelated requests. This makes accidental activation likely and can degrade skill-selection integrity by causing this skill to capture requests it is not specifically designed to handle.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger keywords are broad enough to activate this skill for many generic startup or product-related requests, which can cause inappropriate routing and irrelevant guidance. In an agent system, overbroad activation can override more suitable skills, reduce reliability, and create opportunities for prompt-scope confusion, even though it is not directly a code-execution issue.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The default prompt uses a very broad invocation phrase tied to a wide range of product, business, and implementation tasks, which can cause the skill to be triggered in situations beyond the author's intended scope. Because implicit invocation is enabled, this increases the chance of over-triggering, prompt hijacking through ambiguous user requests, or accidental routing of unrelated conversations into the skill.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger sentences are broad enough to match many ordinary product, business, or planning requests, which can cause the skill to activate outside its intended scope. Over-broad activation is dangerous because it increases the chance that this skill intercepts unrelated prompts, crowds out more appropriate skills, and produces misleading business-validation workflows where the user wanted something else.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.