Qa Defect Lifecycle

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk QA defect lifecycle guidance skill; the only notable issue is broad activation wording that may trigger it more often than intended.

Install if you want a Chinese-language QA defect lifecycle helper. Be aware it may activate for general defect-management wording, so invoke a more specific skill manually if you only want bug reporting, metrics, or retrospective analysis.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The activation condition includes broad trigger phrases such as “缺陷管理”, “Bug管理”, and “缺陷流程”, which may cause the skill to activate in contexts where the user is only discussing defects generally rather than requesting lifecycle management. This can lead to inappropriate skill invocation, context hijacking, or unintended workflow steering, especially in multi-skill environments where precise routing matters.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal