Back to skill

Security audit

Qa Input Validation

Security checks across malware telemetry and agentic risk

Overview

This skill checks whether testing requirements are clear enough before generating test cases, with no evidence of hidden execution, persistence, data exfiltration, or destructive behavior.

Installers should expect this skill to read provided requirement text, uploaded files, or requirement URLs to judge whether enough information exists for test-case generation. Be aware that generic phrases like “help me test” may trigger it in some workflows, so users may need to choose a more specific skill when the request is not about QA requirement validation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation condition is very broad: generic phrases like '帮我测试' and automatic triggering on uploaded requirement documents or URLs can cause this skill to activate for many unrelated conversations. In a multi-skill workflow, this creates unintended routing and can preempt more appropriate skills, leading to incorrect handling of user requests or unnecessary document/URL processing.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal