Back to skill

Security audit

PRD Backlog Conductor

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed requirements-management workflow that stores project backlog files and can run user-directed implementation subagents.

Install only if you want a workflow that maintains a persistent requirements backlog and can dispatch confirmed requirements to background coding agents. Review the global storage path, concurrency setting, and merge behavior so it fits your project workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Confidence
97% confidence
Finding
The description states this is the "English variant" of the skill, which indicates a fixed language choice rather than offering the user a language/locale option. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the constraint is explicitly justified.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.