Back to skill

Security audit

PRD

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward PRD-writing skill that asks clarifying questions and creates Markdown documents in the workspace.

Before installing, expect the skill to create Markdown PRD files in the current workspace. Review or request confirmation of filenames first if overwrites or workspace clutter matter, and avoid putting confidential product details into generated documents unless that workspace is appropriate.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description uses very broad trigger conditions such as helping when a user has an unclear product idea or needs a PRD, which can cause the skill to activate for many ordinary writing and planning requests. Over-broad activation increases the chance of inappropriate invocation and unintended tool use, especially because the workflow later instructs file creation.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to generate multiple files, but it does not clearly warn the user that files may be created or overwritten. In an agent environment with write capabilities, this can lead to unexpected workspace modification, accidental data loss, or unauthorized persistence of generated content.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.