Back to skill

Security audit

AI 测试输出评审

Security checks for vulnerabilities and agentic risk

Overview

This skill is a read-only QA review aid for AI-generated test cases, with one broad auto-activation phrase users should be aware of.

Installers should expect this skill to critique AI-generated test cases and possibly activate on broad review requests. If you only want it for formal QA artifacts, invoke it explicitly around test cases and review its suggestions before deleting, merging, or changing any real test data.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
92% confidence
Finding
The skill auto-activates on very broad phrases such as '检查一下输出', '自动检查', and similar everyday review requests. This can cause the skill to trigger in contexts broader than intended, leading to unexpected behavior, workflow hijacking, or accidental processing of unrelated user content. The surrounding skill content increases concern because it presents itself as a mandatory gate ('必过门禁') after AI output, which amplifies the effect of overbroad activation.

Static analysis

No suspicious patterns detected.