generate-model-ready-test-cases-cn

Security checks across malware telemetry and agentic risk

Overview

This skill is a focused Chinese test-case generator with a local JSON validator and no evidence of hidden access, persistence, or unsafe behavior.

Install is reasonable if you want Chinese, structured JSON test suites. Review any generated tests before letting another agent execute them against real systems, especially for production, payment, deletion, bulk-change, or other irreversible workflows.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The default prompt is broadly phrased to invoke the skill whenever the user has requirements, prototypes, or interface descriptions, but it does not define clear boundaries, scope limits, or user-confirmation conditions. In an agent system, overly broad activation can cause unintended invocation on unrelated inputs, increasing the chance of inappropriate data processing, wrong-language responses, or accidental use in contexts where safer or more specific handling is needed.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill metadata and prompt enforce Chinese-language usage without indicating that this should depend on the user's preference or locale. While not directly enabling code execution or data exfiltration, it can cause incorrect or inaccessible outputs, misalignment with user expectations, and downstream automation errors if other agents or tools expect another language.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal