Back to skill

Security audit

B2b Pm Workbench 1.1.0

Security checks across malware telemetry and agentic risk

Overview

This is a content-heavy B2B product-management workbook skill, with no executable code or hidden high-impact behavior found.

Install only if you want a broad B2B product-management assistant. Expect it to influence many PM-related prompts and to add its own disclaimer/footer. Do not put confidential customer interviews, employee names, budgets, internal systems, or procurement details into generated templates unless your organization permits that use; anonymize where practical and verify business, legal, and technical claims before relying on them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The README instructs users to 'directly describe需求' and advertises very broad trigger phrases, which can cause the skill to activate for many ordinary product-management conversations. Overly broad invocation increases the chance of unintended context capture, unexpected agent behavior, or accidental routing to this skill when a narrower skill or no skill should be used.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list contains many broad, commonly used B2B/PM terms such as PRD, roadmap, workflow, and product architecture. This can cause the skill to activate in conversations where the user did not intend to invoke it, increasing prompt-scope hijacking risk and making the assistant follow this skill's extensive instructions unexpectedly.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation guidance says users can simply 'tell me what you want to do' and that the skill will automatically match phases, methods, and tools. This is ambiguous and overbroad, so ordinary PM-related requests may implicitly activate the skill without clear consent, causing hidden instruction takeover and unexpected tool-routing behavior.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The template explicitly captures personal and organizational data such as company name, interviewee name, role, and contact-context information, but it provides no guidance on consent, retention, minimization, or secure handling. In a B2B product-management workflow, these notes can easily include sensitive business information and identifiable employee data, creating privacy, compliance, and confidentiality risks if copied into shared docs or AI systems without controls.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.