Back to skill

Security audit

Qa Output Validation

Security checks across malware telemetry and agentic risk

Overview

This skill is a scoped quality-check helper for generated test cases, with no evidence of hidden execution, persistence, or data exfiltration.

Install this if you want an agent to add a final validation pass over generated QA test cases. Be aware it may activate automatically in that workflow and can read files the agent chooses for validation, so use it in projects where read-only inspection of relevant requirement and test artifacts is acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The auto-activation condition 'AI生成测试用例后、最终输出前自动激活' is broad and lacks explicit scoping, exclusions, or preconditions. In an agent pipeline, this can cause the skill to run on unintended inputs or contexts, potentially overriding normal workflow boundaries, consuming resources, or validating content that was never meant for this stage.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal