Qa Exploratory Testing

Security checks across malware telemetry and agentic risk

Overview

This is a plain Chinese-language exploratory QA testing guide with no executable payload or hidden behavior.

Install this if you want a Chinese-language QA aid for exploratory testing. Keep it scoped to systems you own or are authorized to test, and review any proposed Bash commands before running them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The activation condition uses broad natural-language triggers such as 用户说“探索测试”、“自由测试”、“漫游测试” or needing to find issues missed by scripted testing. This can cause the skill to activate in loosely related contexts, increasing the chance of unintended tool use or the wrong testing workflow being applied, though it does not by itself contain direct code-execution or data-exfiltration behavior.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The skill metadata and body are written to operate in Chinese without indicating that output language should follow user preference. This can lead to misunderstandings, incorrect execution of testing instructions, or inaccessible results for users who do not read Chinese, which is a reliability and usability risk rather than a direct security exploit.

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal