Back to skill

Security audit

FDE PRD Writer

Security checks across malware telemetry and agentic risk

Overview

This skill is a purpose-aligned PRD writing aid with a local traceability checker and no evidence of hidden data access, persistence, or unsafe automation.

Before installing, users should understand that this skill helps draft PRD handoff packages and can run a local checker against a PRD file they provide. Review any generated Agent Skills handoff text carefully, especially triggers, inputs, tool boundaries, and manual validation gates, because those choices affect downstream agent behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The agent-skills handover section asks for 'Trigger, input and expected output' but provides no concrete constraints, allowed sources, trust boundaries, or validation requirements. In a skill that defines downstream agent behavior, this ambiguity can lead authors to specify overly broad triggers or unconstrained inputs, increasing the risk of prompt injection, unintended invocation, or unsafe automation being passed downstream as accepted requirements.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.