Back to skill

Security audit

Product Validation Planner

Security checks for vulnerabilities and agentic risk

Overview

This documentation-only skill gives product validation planning guidance; its triggers are broad, but it does not contain hidden commands, persistence, credential use, or data access.

Install this if you want structured help validating product ideas. Be aware that its broad implicit triggers may make it appear in unrelated startup, SaaS, prototype, or validation discussions; narrowing triggers or invoking it explicitly would reduce accidental activation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is broad enough to match many ordinary business, product, and workflow requests, which increases the chance the agent invokes this skill when a more appropriate or safer skill should handle the task. Over-broad routing can cause prompt-scope confusion, accidental instruction override, and unintended access to contextual materials, even if the content itself is not overtly malicious.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Generic trigger keywords like 'validation', 'prototype', 'saas', and 'startup' are common across many unrelated requests, so they are unsafe as primary routing signals. This can lead to frequent false activations, causing the agent to apply the wrong workflow or expose users to irrelevant or conflicting guidance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger sentence uses very broad natural-language phrasing ('Help me...') that can match many ordinary user requests unrelated to this specific skill. In an agent routing context, this can cause accidental invocation, prompt-scope expansion, and unintended exposure of the skill's instructions or outputs in situations where a narrower skill should have been selected.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The invocation guidance is ambiguous and overly permissive, including generic workflow language and a broad 'Use $product-validation-planner to handle...' pattern without clear scope boundaries. This increases the chance of misrouting unrelated requests into this skill, which can override more appropriate controls or cause the agent to produce business-planning outputs from weak or unintended user signals.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad, generic requests such as asking for a practical workflow or help with product ideas, which can match many ordinary conversations outside the intended scope. This increases the chance of unintended skill activation, causing the agent to route users into this skill when they did not explicitly request it and potentially overriding more appropriate or safer behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger section provides only broad keywords and positive examples, without meaningful negative examples or boundary conditions that constrain activation. Without explicit 'do not use when' guidance, the orchestrator may over-apply the skill to adjacent domains, increasing misrouting risk and reducing reliability.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description and activation guidance are broadly scoped around common business terms, making it easy for the orchestrator to invoke this skill for many loosely related requests. Overbroad triggering can cause misrouting, inappropriate task handling, and prompt-context pollution, which is a genuine security/control issue in agent systems even without obviously malicious content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The keyword list uses highly generic terms such as business-and-operations, validation, prototype, saas, and startup without boundaries or disambiguation. In an agent environment, this increases accidental activation on unrelated conversations, which can override more appropriate skills or inject irrelevant instructions into downstream reasoning.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The default prompt uses a very broad invocation phrase tied to a wide range of common business/product topics, which increases the chance of unintended or automatic activation in contexts where the user did not explicitly request this skill. Because implicit invocation is enabled, this can cause over-triggering, unexpected agent behavior, and potential prompt-surface expansion into user workflows that were not meant to involve this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger sentence begins with a very broad, everyday phrase ('Help me ...'), which can cause the skill to activate for unrelated user requests. In an agent-routing context, overly generic triggers increase the chance of incorrect invocation, prompt confusion, and unintended exposure of the skill's instructions or behavior in contexts where it does not belong.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.