Back to skill

Security audit

prd-design

Security checks across malware telemetry and agentic risk

Overview

This is a product-design workflow skill that generates PRD, prototype, RBAC, and tracking-plan files; its risks are mainly overbroad routing and handling sensitive project materials, not hidden or malicious behavior.

Install only if you want a structured Chinese-language PRD/product-design workflow. Before using it, redact secrets, credentials, customer data, and regulated personal information from DDLs, screenshots, and documents; also review generated analytics/tracking plans and project files before treating them as implementation requirements.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger list is broad enough to match many ordinary product-discussion requests, which can cause this skill to activate outside its intended scope and steer conversations into a rigid 0→1 internal-system workflow. In an agent setting, overbroad routing is a security and safety concern because it can override user intent, mis-handle unrelated tasks, and propagate incorrect downstream actions or outputs.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list includes broad terms like '迭代、加功能、改功能' that can appear in ordinary conversation and may cause this routing skill to activate when the user did not intend to invoke product-design behavior. In a router skill, accidental invocation is security-relevant because it can override normal handling, lock the session into a workflow, and redirect user input to other skills based on weak lexical matches.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The routing rules rely on ambiguous keywords such as '改造', '从零', and '改一下' without scope constraints, making misrouting likely when users discuss unrelated tasks. Because the file also states that routing becomes fixed for the session and later adjustment requests must stay within the chosen skill, a wrong initial match can persist and distort subsequent behavior, increasing the operational and safety impact.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list includes very broad everyday terms such as “改一下” and similar generic modification language, which can cause the router to invoke this skill for unrelated requests. In an agent setting, over-broad activation can misroute user intent, apply the wrong workflow constraints, and produce unintended file generation or process actions based on incorrect assumptions about the task.

Missing User Warnings

Low
Confidence
90% confidence
Finding
The skill instructs the agent to create `project/00-input/baseline.md` directly as part of the workflow, but it does not require an explicit user confirmation immediately before performing that write. Even though this is a relatively low-risk project-local file operation, silent file creation/modification can surprise users, overwrite prior work, or normalize unsafe write behavior in broader skills.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly asks users to provide broad project documents, flowcharts, text descriptions, and screenshots, but gives no warning to avoid secrets, personal data, credentials, or regulated information. In a product-design routing skill, this increases the chance that users upload sensitive internal artifacts for AI processing unnecessarily, creating data exposure and over-collection risk.

Missing User Warnings

Low
Confidence
80% confidence
Finding
The step directs creation of `project/01-adjustment-list.md` without checking whether the file already exists or warning that existing workspace content could be overwritten. While this is mainly an integrity and safety issue rather than a classic security flaw, it can still cause unintended modification or loss of user data in the workspace.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill instructs the agent to autonomously generate and save a tracking plan without user confirmation, including inferred events and metrics. In a product-design router context, this can normalize silent specification of analytics collection that may later drive implementation involving personal data, sensitive business telemetry, or compliance-relevant monitoring without explicit review.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.