Back to skill

Security audit

根据PRD或者你的测试用例来编写和修改测试用例

Security checks across malware telemetry and agentic risk

Overview

This skill is a test-case writing assistant with instructions that match its stated purpose and no evidence of hidden execution, data exfiltration, persistence, or destructive behavior.

Safe to install for drafting and improving test cases. Be aware it may trigger on broad testing language, so confirm intent when a conversation only casually mentions testing, and avoid providing sensitive production data unless you intend the agent to use it as test-design input.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill declares it should trigger whenever users mention broad, common testing terms such as '测试用例', '功能测试', or '测试计划'. That can cause unintended activation during ordinary conversation, making the agent route requests into this skill without clear user intent and potentially overriding more appropriate behavior or causing surprising file/tool use.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.