Back to skill

Security audit

移动端测试

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only Chinese mobile QA testing guide, with no hidden execution, persistence, credential handling, or data exfiltration behavior found.

Install this if you want Chinese-language mobile QA checklist and test-case planning guidance. Be aware that it may activate for broad mobile or app testing requests, and its guidance is primarily Chinese; review or adjust the trigger and language behavior if you need stricter routing or multilingual output.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill's invocation triggers include broad phrases such as mobile/app testing requests that can overlap with many ordinary user intents, increasing the chance the skill is auto-invoked in contexts where it is not the best fit. Misrouting is not a code-execution issue, but it can cause incorrect workflow selection, irrelevant guidance, and downstream confusion in agent behavior.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill is authored entirely in Chinese and its output requirements are phrased as mandatory Chinese formatting, without any documented locale constraint or user-consent mechanism. This can cause unintended language coercion, reducing usability and potentially leading to misunderstanding of test guidance, especially in multilingual environments or automated pipelines expecting another language.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.