Back to skill

Security audit

Workflow Dlc Pm Requirement

Security checks across malware telemetry and agentic risk

Overview

This PRD-writing skill is mostly coherent, but it automatically stores sensitive project workflow details in a persistent local log without clear opt-out or retention controls.

Install only if you are comfortable with the skill creating or updating PRD-related files and Feishu documents, reading scoped project materials you provide, and writing a persistent local experience log. For confidential projects, disable or manually remove the experience-base log, avoid giving broad repository access, and review any generated document links before sharing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Context-Inappropriate Capability

Medium
Confidence
82% confidence
Finding
The skill expands from PRD authoring into active external information gathering via WebFetch/WebSearch. That capability is broader than necessary for the stated purpose and can cause unintended network access, external data ingestion, and policy bypass if invoked on sensitive or user-supplied targets.

Context-Inappropriate Capability

Medium
Confidence
84% confidence
Finding
The skill claims it can read an existing code repository to summarize functionality, which materially broadens scope from document drafting to source analysis. If the agent has repository access, this can expose proprietary code and internal logic to a workflow that does not clearly need that level of access.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The workflow writes a persistent JSON log containing project name, PRD URL, iteration details, and workflow outputs, but this retention is not disclosed in the manifest. Undisclosed persistence of user/project data creates a transparency and privacy issue and increases the chance of later leakage from shared storage.

Vague Triggers

Medium
Confidence
72% confidence
Finding
Broad trigger phrases such as everyday requests to 'write PRD' or 'do requirements' increase the chance of accidental invocation in contexts the user did not intend. Unintended activation matters here because the skill can create documents, read local assets, and instruct follow-on actions, amplifying the effects of misrouting.

Ssd 3

Medium
Confidence
94% confidence
Finding
The persistent experience log stores natural-language project workflow details, which may include sensitive business context, links, and decision history. Because the skill is for PM/PRD work, the logged content is especially likely to contain confidential product plans, making retention more dangerous than in a low-sensitivity domain.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.