Gen Prd

Security checks across malware telemetry and agentic risk

Overview

This skill is a PRD-writing helper that creates local Markdown documentation, with no evidence of hidden execution, credential use, or data exfiltration.

Install this if you want an agent to interview you for product requirements and write a PRD Markdown file locally. Review or set the output path before generation, and pause the workflow if you do not want it to continue into the follow-on design step.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs the agent to create directories and write files to disk as a mandatory action, but it does not require explicit user consent at the point of filesystem modification. In agent environments with write capabilities, this can cause unintended persistent changes to a repository or workspace, especially if the skill is triggered from ambiguous prompts or chained automatically from another skill.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal