Back to skill

Security audit

industrial-testcase-generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed industrial test-case generator that reads user-provided requirements and creates an Excel test-case workbook.

Install only if you want an agent to process industrial requirements and generate local Excel test-case files. Review generated workbooks before sharing them, especially if the input requirements contain proprietary plant, device, or security details.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill advertises activation on a very broad set of industrial keywords, including generic terms like device monitoring, remote maintenance, and industrial testing. Over-broad triggers can cause unintended invocation in unrelated or mixed-context conversations, which may lead to inappropriate handling of sensitive documents or unexpected file-generation behavior without clear user intent.

Missing User Warnings

Low
Confidence
86% confidence
Finding
The skill states that it will output a structured Excel test case file, but it does not clearly require notifying the user before creating or writing that file. This can surprise users, create unintended artifacts from sensitive requirement documents, and reduce transparency around local file operations.

Static analysis

No suspicious patterns detected.