Back to skill

Security audit

B2b Pm Workbench International

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-heavy B2B product management skill with no executable code or hidden data access, though users should be careful with enterprise data when following its AI-tool and interview guidance.

Install only if you want a broad B2B product-management reference skill. When using it with real company work, do not paste confidential customer data, contracts, credentials, screen contents, or regulated information into external AI tools unless your organization approves it; get consent before observing client workstations or screens.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger language is extremely broad ('Just describe your need') and encourages automatic phase/methodology matching without clear boundaries or user confirmation. In an agent skill context, this can cause unintended activation for loosely related prompts, increasing the chance the skill injects irrelevant instructions or takes over workflows unexpectedly.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill ends with a generic activation cue telling users to 'directly tell me what you want to do,' while advertising very broad capabilities across strategy, documents, prototypes, diagrams, and toolchains. That broad trigger surface can cause the skill to activate on ordinary product- or business-related requests without clear user intent to invoke this specific skill, increasing the chance of unintended tool orchestration or policy override via the skill's embedded instructions.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The guidance explicitly recommends pasting competitor help documentation, pricing pages, and inferred operational data into external AI tools without any warning about confidentiality, contractual restrictions, privacy, or data residency. In a B2B PM workbench context, users are likely to handle sensitive customer, partner, and market materials, so normalizing external transmission can cause unauthorized disclosure or compliance violations even if no direct exfiltration mechanism is embedded.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The model-selection section treats closed-source API usage as a standard option for enterprise data and notes that data is sent externally, but it does not pair that with operational safeguards or warnings about privacy, confidentiality, retention, cross-border transfer, or vendor training/use policies. Because this skill is aimed at enterprise product design, readers may adopt the pattern as-is and route regulated or proprietary data to external providers inappropriately.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The memory engineering section recommends persistent storage of user preferences, history, and business facts but omits basic privacy and security constraints such as purpose limitation, consent, retention, access control, deletion rights, and segregation by tenant. In a multi-tenant B2B environment, poorly governed long-term memory can accumulate sensitive personal and commercial data, increasing breach impact and creating compliance exposure.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The template explicitly advises interviewers to observe a client's workstation, screen, and operations, but it does not instruct them to obtain informed consent, avoid viewing sensitive data, or comply with privacy/confidentiality obligations. In a B2B setting, this can lead to unnecessary exposure of customer data, credentials, regulated information, or trade secrets during interviews and shadowing sessions.

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
references/complete-product-lifecycle.md:760