Qa Ai Blindspot Compensation

Security checks across malware telemetry and agentic risk

Overview

This is a read-only QA checklist skill that may trigger on broad testing phrases but does not run code, access secrets, or persist data.

Installers should understand that this skill may activate for general testing-coverage questions, so it can add extra QA workload. It is otherwise low risk: it reads context and produces supplemental test cases without executing commands, changing files, or handling credentials.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation condition includes broad user phrases such as '还有什么没测到', 'AI漏了什么', and '全面覆盖', which are common in normal QA conversations and could cause the skill to trigger when the user did not specifically request this specialized workflow. Unintended activation can distort the agent's behavior by overproducing test cases, changing process routing, or adding unnecessary workload, especially in multi-skill orchestration contexts.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal