qa-engineer-assistant
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's files, instructions, and included script are consistent with a QA/test-assistant: it requests no credentials or unusual installs and the bundled generator only writes local pytest boilerplate and a conftest with placeholder values.
This skill appears coherent and not malicious, but take these precautions before running it: 1) Inspect the generated files (tests and conftest.py) and replace the placeholder base_url, username, and password with safe test credentials — do not run against production systems. 2) The generator will write files to the chosen output directory (default ./tests); ensure you run it in an appropriate workspace and commit only what you intend. 3) If you use the generated tests, review network targets and sensitive data handling (tokens, logs) before executing in CI. 4) No environment variables or remote installs are required by the skill itself; treat the included code as a local boilerplate generator and validate it per your security policies.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
