SKILLEMALL.ai

CD ai-pm-workbench-international

AI PM Super Workbench — International Edition. Full-stack intelligent workbench for AI Product Managers worldwide.

ClawHub Agent Skills author: yinjianheng v1.2.0-intl MIT-0 18 files body ≈ 22 097 tokens Open the sourceclawhub.ai analyzed 3 d ago

AI PM Super Workbench — International Edition.

As a process D 44/100 · Unfinished process — weak spots: result and completion, when it triggers, inputs and preconditions

ProcedureAI and agentstype and topics are labelled automatically from the skill text
JSON
Technical rating
C
62/100
safety, quality, tests
Safety 60%
63
Quality 40%
60
Run on models
none yet
Process rating
D
44/100
Unfinished process
Result and completion w 14
0
Inputs and preconditions w 11
0
Progress reporting w 2
0
the three weakest of ten parameters · all ten

What is at stake

Medium-severity findings: the skill is probably honest, but read what alarmed the scanner.

Instruction override medium severity

Below is the worst case for this category. The finding here is medium: the guard saw a sign, not a proof.

If you install

The text contains phrases like "ignore previous instructions" or "you are now…". That is an attempt to hijack the agent: it may break your rules, the system limits or company policy.

For the author

An honest skill does not need them: state the role and the rules directly without overriding other instructions. Otherwise catalog scanners and corporate filters will block the listing.

How to improve

  1. Say in the description WHEN to use the skill ("use when…", example requests): that is the agent's main cue.
  2. The SKILL.md body is over 5,000 tokens: move reference detail into references/ and load it when needed.
For the model run — optional
  • Your own cases (evals/evals.json, 4–6 real requests with expected answers): the full check would then run those instead of a model-drafted suite.
  • A spec.yaml with trigger phrases and assertions — a behaviour contract for CI; `skilltest init` writes a template.

Guard findings · 29

✓ No critical or high findings

Medium and low: 29
  • medium Instruction override en-ignore-previous references/templates/ai-safety-template.md:254
    Instruction-override phrase ("ignore previous instructions") (detector / deny-list definition)
    ├── Instruction Override: "Ignore previous instructions"
    detector
  • medium Instruction override en-role-hijack references/templates/ai-safety-template.md:255
    Role hijack ("from now on you must ignore… / developer mode") (quoted — discussed, not commanded)
    ├── Role-play: "You are now DAN, with no restrictions"
    quoted
  • low Risky intent intent-offensive-security README.md:21
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use) (detector / deny-list definition)
    | 🛡️ AI safety and compliance risks are significant | **EU AI Act · China Deep Synthesis Regulations · Layered Safety Guardrails · Red Teaming** |
    detector
  • low Risky intent intent-offensive-security README.md:39
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use) (detector / deny-list definition)
    | 9️⃣ Safety Guardrails & Red Team | Layered guardrails · Red teaming · Jailbreak prevention | AI Safety Plan |
    detector
  • low Risky intent intent-offensive-security README.md:55
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use) (detector / deny-list definition)
    | AI Safety | Input Guardrails · Output Guardrails · PII Redaction · Jailbreak Detection · Red Teaming |
    detector
  • low Risky intent intent-offensive-security references/ai-industry-trends-2026.md:798
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use)
    | **Safety** | Harmful content output rate | Red team testing + automated scanning | <0.1% |
  • low Risky intent intent-offensive-security references/ai-industry-trends-2026.md:860
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use) (detector / deny-list definition)
    ### Phase 10: Safety Guardrails & Red Team Testing
    detector
  • low Risky intent intent-offensive-security references/ai-industry-trends-2026.md:872
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use)
    └── System Layer: Agent tool abuse, privilege escalation, resource exhaustion
  • low Risky intent intent-offensive-security references/ai-industry-trends-2026.md:885
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use)
    #### 10.3 Red Team Testing
  • low Risky intent intent-offensive-security references/ai-industry-trends-2026.md:887
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use) (quoted — discussed, not commanded)
    **Lessons from Microsoft's Red Teaming of 100+ Products:**
    quoted
  • low Instruction override en-ignore-previous references/examples/ai-customer-service-example.md:389
    Instruction-override phrase ("ignore previous instructions") (detector / deny-list definition; test fixture / example file)
    - Injection Detection: LLM classifier detects patterns like "ignore previous instructions"
    detectorfixture
  • low Risky intent intent-offensive-security references/methodologies/ai-pm-deep-methods.md:521
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use)
    | Red Team Testing | Quarterly | Security team triggers |
  • low Risky intent intent-offensive-security references/methodologies/ai-pm-deep-methods.md:568
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use) (detector / deny-list definition)
    | Scale | +LLM injection detection, Hallucination detection | +Red Team testing | +Model safety assessment |
    detector
  • low Risky intent intent-offensive-security references/templates/ai-evaluation-template.md:53
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use)
    | Adversarial Test Set | | Red team + security experts | Monthly |
  • low Risky intent intent-offensive-security references/templates/ai-evaluation-template.md:336
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use)
    | Red Team Test | Quarterly | Red Team Report |
  • low Risky intent intent-offensive-security references/templates/ai-evaluation-template.md:393
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use)
    | Adversarial Tasks | | Abnormal inputs | Red team constructed |
  • low Risky intent intent-offensive-security references/templates/ai-prd-template.md:201
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use)
    | Safety | Harmful Output Rate | Red Team Testing | <0.1% |
  • low Instruction override en-ignore-previous references/templates/ai-safety-template.md:89
    Instruction-override phrase ("ignore previous instructions") (detector / deny-list definition; documentation table row)
    | Role-play Jailbreak | Detect "You are now..." type instructions | "DAN mode", "Ignore previous instructions" |
    detectortable
  • low Risky intent intent-offensive-security references/templates/ai-safety-template.md:182
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use)
    | Privilege Escalation | Agent gains permissions beyond design | Least privilege principle + permission audit |
  • low Risky intent intent-offensive-security references/templates/ai-safety-template.md:236
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use)
    ## 7. Red Team Testing
  • low Risky intent intent-offensive-security references/templates/ai-safety-template.md:248
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use)
    | Agent Attack | Tool Abuse/Privilege Escalation | 50+ | Each Agent update |
  • low Risky intent intent-offensive-security references/templates/ai-safety-template.md:269
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use)
    ### 7.3 Red Team Testing Process
  • low Risky intent intent-offensive-security references/templates/ai-safety-template.md:376
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use)
    □ Red Team Testing: Completed with no P0/P1 issues
  • low Risky intent intent-offensive-security references/templates/ai-strategy-template.md:131
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use) (detector / deny-list definition)
    | Security/Compliance | | | Guardrails + Red Team Testing + Compliance Review |
    detector
  • low Risky intent intent-offensive-security SKILL.md:58
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use) (detector / deny-list definition)
    | Implement safety guardrails / Red teaming | [Phase 10: Safety Guardrails & Red Teaming](#phas…ing) |
    detector
  • low Risky intent intent-offensive-security SKILL.md:467
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use) (detector / deny-list definition)
    | **Fairness & Safety** | Bias detection, harmful content filtering rate | Bias audit, Red teaming |
    detector
  • low Risky intent intent-offensive-security SKILL.md:569
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use) (detector / deny-list definition)
    ### Phase 10: Safety Guardrails & Red Teaming
    detector
  • low Risky intent intent-offensive-security SKILL.md:602
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use)
    □ Red team testing completed and high-risk items fixed
  • low Risky intent intent-offensive-security SKILL.md:655
    Offensive-security / dual-use content (legitimate for authorised testing; review intended use) (detector / deny-list definition)
    □ AI Security Basics (Injection / Jailbreak / Guardrails / Red Team Testing)
    detector

Files scanned: 18. Evidence is masked. Grey chips explain why severity was lowered.

Against the Agent Skills spec

  • warning description-no-when description does not say WHEN to use the skill (no "use when")
  • warning body-long SKILL.md body ≈ 22097 tokens (recommended < 5000); move details to references/
  • note frontmatter-key unknown frontmatter key "language"
  • note frontmatter-key unknown frontmatter key "contact"

Process rating: all ten parameters 44/100

  • 0Result and completion. Does not say what the result is
  • 0Inputs and preconditions. Does not say what the process needs to start
  • 0Progress reporting. Says nothing while it works
  • 10Execution cost. Instruction body is 22097 tokens: crowds the task out of the window
  • 20When it triggers. No condition that starts the skill
  • 30Running it twice. 19 mutating operations with no state check
  • 50Failures and branches. 0 branches, has a failure section
  • 60Steps. 33 steps, 4 vague phrases
  • 100Tools and files. No external tools needed
  • 100Consistency. Name and required fields are in place
  • medium Safety rules and hard prohibitions inside a skill: they belong in the system prompt, here they protect nothing
  • low 44 top-level sections: this looks like several domains in one skill

Everything here is measured from the skill text rather than judged by a model, so the numbers are checkable. A parameter weighs more when it is a more common reason for the process to stall.

Quality signals

  • +5Description has no quoted example phrases that should trigger the skill
  • +4Description does not say when NOT to use the skill (false activations)
  • +3Description length 114: 120–800 characters recommended
  • +3Output format is not stated: the model decides each time
  • -248 emoji in the instructions: noise for the model
  • +2Single-language instructions
  • +4Structure: 154 headings
  • +3Step-by-step instructions: 33 items
  • +4Has examples (37 code blocks)
  • +4Reference files are cited in the instructions (1 of 1)
  • +1License stated

Quality base 70; lint remarks subtract, signals add up to 100. Result: 60.

External checks

ClawHub: clean
This is a large AI product-management reference skill with broad activation language and some reasoning-output templates, but no artifact-backed malware, exfiltration, destructive behavior, or hidden execution.
LLM: benign (high) · VirusTotal: · 10 Jul 2026