Back to skill

Security audit

test-review

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed test-review guide whose repo-reading and test-running instructions fit its purpose, with only minor activation-scope caveats.

Before installing, note that the skill may activate on general testing or quality conversations. Review any suggested test, coverage, or package-install commands before allowing them to run, especially in large or sensitive repositories.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The manifest trigger list includes generic words like "testing," "coverage," and "quality," which are common in ordinary developer conversation and not specific enough to this skill. Because no tighter activation constraints or exclusion examples are provided, these triggers could overlap with unrelated requests and cause accidental invocation.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger "auditing test quality or before a major release" describes a broad situation rather than a precise invocation phrase, making it unclear exactly what user wording should activate the skill. This ambiguity increases the chance of unintended activation during routine release or QA discussions.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.