Back to skill

Security audit

Component Testing

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward frontend testing guidance skill with no hidden persistence, credential use, or unsafe behavior found.

Install this if you want help writing or reviewing frontend UI/component tests. Because the trigger text includes generic testing phrases, confirm it is being used for frontend component or UI-adjacent tests rather than broad test strategy, E2E, or validation-fix work.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

md
- ID: `fec-component-testing`
- Category: `testing`
- Version: `2.9.0`
- Source: `skills/fec-component-testing/SKILL.md`

## Description

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says Chinese triggers include "unit testing" and "lightweight integration testing," which are broad phrases that can match many ordinary development requests beyond this specific frontend component-testing skill. The README does not provide clear activation boundaries, explicit trigger lists with constraints, or negative examples to distinguish when this skill should not be invoked.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description uses broad trigger phrases such as 'component testing', 'unit testing', and 'lightweight integration testing', which are common terms that may cause the agent to invoke this skill in contexts where a different workflow would be more appropriate. Over-broad activation can degrade security and reliability by misrouting user requests, bypassing more specialized validation or planning workflows, and increasing the chance of incorrect or unsafe task execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger text includes broad phrases such as "unit testing" and "lightweight integration testing," which can cause the skill router to activate this skill for many generic testing requests outside its intended frontend component/UI scope. Misrouting is dangerous because it can steer users away from more appropriate workflows (such as strategy, validation, or E2E) and produce incorrect or incomplete guidance for security- or quality-relevant tasks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description lists triggers such as "component testing" and especially "unit testing," which are broad phrases commonly used in everyday developer requests. Because the manifest does not provide explicit exclusion examples beyond a brief workflow preference note, the invocation scope may still be ambiguous and cause unintended activation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The description explicitly states that Chinese triggers include several phrases, but it does not present this as an optional locale choice or explain a region-specific requirement. This can be interpreted as a language/locale policy issue because the file hard-codes language-specific invocation behavior without documenting user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.