Back to skill

Security audit

Workflow Dlc Pm Review

Security checks across malware telemetry and agentic risk

Overview

This is a non-executable PRD review workflow skill with no evidence of hidden data access, persistence, or unsafe actions.

Install this if you want a structured PRD review workflow. Be aware that generic phrases like “组织 review” or “三端对齐” may invoke a heavier multi-phase process than intended, so ask the agent to keep the review lightweight when that is what you want.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases include broad, common project-management terms such as '组织 review', 'PRD 评审', and '三端对齐', which can plausibly appear in ordinary user requests outside the intended workflow. This can cause unintended activation of the skill, leading the agent to inject a rigid multi-phase process or call other specialized agents when the user only wanted lightweight advice, creating workflow confusion and overreach.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.