Back to skill

Security audit

QA测试主管 质量门禁验收

Security checks for vulnerabilities and agentic risk

Overview

This is a QA review skill that guides an agent to inspect test evidence and recommend release readiness, without installing code or requesting hidden access.

Safe to install for QA gate review use. Before using it, confirm the referenced Weline project documents and notification expectations fit your workspace, and avoid sharing secrets or unnecessary sensitive data in test logs, runtime evidence, or QA reports.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.