Back to skill

Security audit

Product Manager

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only Product Manager persona skill with no code, installs, credentials, or hidden data access.

Before installing, treat it as an advisory Product Manager persona: useful for planning and product documents, but its recommendations should still be reviewed by a human before changing roadmaps, commitments, or launch plans.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The instruction "Reference this agent by name or specialty when you need its expertise" does not define specific trigger phrases or clear boundaries for when the skill should activate. Because "specialty" and "need its expertise" are broad and context-dependent, the skill could be invoked by common product-related conversation rather than an intentional request.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.