Back to skill

Security audit

Phy Prd Writer

Security checks across malware telemetry and agentic risk

Overview

This is a coherent PRD-writing assistant with disclosed follow-on workflow steps, but users should approve any saving, committing, or implementation actions.

Reasonable to install for PRD drafting. Keep it read-only until you explicitly want a file saved, review the destination path and content before allowing a git commit, and treat design, architecture, task creation, and implementation steps as separate approvals.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill’s stated purpose is PRD drafting, but it also directs follow-on actions that can modify the repository, create commits, generate tasks, and drive implementation workflow. This scope expansion is risky because a user invoking a documentation assistant may not expect write actions or orchestration into code-changing subagents, increasing the chance of unintended repository changes and over-privileged behavior.

Context-Inappropriate Capability

Low
Confidence
77% confidence
Finding
The instruction to search local podcast transcripts introduces access to unrelated local content that is not necessary for drafting a PRD. Even if intended as enrichment, unnecessary local search broadens data exposure and can cause the skill to retrieve sensitive or irrelevant files from the user environment.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrase 'new feature' is extremely broad and can match ordinary conversation unrelated to invoking a PRD workflow. Overbroad activation is dangerous because it can unexpectedly launch a multi-step agent behavior, including downstream suggestions for file changes and task orchestration, without clear user intent.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill tells the agent to save a PRD and create a git commit without prominently warning that these actions modify files and repository history. In context, this is especially risky because users may think they are only generating a document outline, not authorizing persistent changes to their workspace and VCS state.

VirusTotal

No VirusTotal findings

View on VirusTotal

Static analysis

No suspicious patterns detected.