Back to skill

Security audit

Ai Pm Workbench International

Security checks for vulnerabilities and agentic risk

Overview

This is a large AI product-management reference skill with broad activation language and some reasoning-output templates, but no artifact-backed malware, exfiltration, destructive behavior, or hidden execution.

Install only if you want a broad AI product-management assistant. Expect it to steer many AI PM, RAG, agent, evaluation, pricing, and compliance requests and to add a long legal/author disclaimer unless your agent constrains that behavior. For production prompt templates, revise the Chain-of-Thought and reasoning fields to return concise user-safe explanations rather than hidden internal reasoning.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger guidance is very broad ('just describe your need') and spans many generic product, architecture, evaluation, pricing, and security topics. In skill-based agent environments, this can cause accidental invocation in unrelated conversations, exposing the model to unintended instructions or causing it to steer work without explicit user intent.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill repeatedly invites users to 'tell me directly what you want to do' without any explicit invocation boundary, which makes ordinary product-management requests likely to activate the skill unintentionally. In a multi-skill environment, this can cause overbroad routing, prompt hijacking of unrelated tasks, and unwanted application of the skill's heavy instructions and output constraints.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The example trigger phrase 'Help me design an AI customer service chatbot product' is a normal user request, not a unique skill invocation. Because the phrase is generic and aligned with common PM workflows, it increases the chance the skill captures broad classes of benign requests and overrides more appropriate system behavior.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The repeated 'Get started: Tell me directly what you want to do' language reinforces a catch-all activation model with no boundary conditions. This broadens the skill's effective scope and can cause accidental triggering across many unrelated or only partially related user prompts.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The metadata hard-codes 'language: en-US', which can force locale or language behavior without user consent. While not directly dangerous in the exploit sense, it can override user preferences, reduce accessibility, and create unsafe misunderstandings for multilingual or region-specific compliance content.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The template explicitly encourages Chain-of-Thought design and verification, including example reasoning traces, but does not warn authors not to expose internal reasoning to end users. In an agent/prompt-engineering workbench, this can normalize collecting, storing, or returning hidden reasoning, which may leak sensitive context, system instructions, policy logic, or intermediate deliberation that should remain internal.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The structured output schema defines a free-form 'reasoning' field without any caution that it may expose confidential intermediate analysis, hidden instructions, retrieved sensitive data, or safety decision logic. Because this is a reusable template, downstream teams may operationalize the field across products, increasing the chance of systematic reasoning leakage in production responses or logs.

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
references/ai-industry-trends-2026.md:401

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
references/examples/ai-customer-service-example.md:389

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
references/methodologies/ai-pm-deep-methods.md:213

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
references/templates/ai-safety-template.md:89

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
references/templates/prompt-engineering-template.md:380