Back to skill

Security audit

Qa Requirement Review

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only BRD requirements review skill with no evidence of hidden code, credential access, persistence, or unsafe side effects.

Install this if you want Chinese-language BRD review guidance. Be mindful that broad phrases like requirement review may trigger it more often than intended, and avoid sharing confidential business requirements in environments you do not trust.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation trigger is broad and keyword-based (e.g., any mention of '需求评审', '评审需求', '需求质量'), which can cause the skill to activate in contexts where the user did not actually request this workflow. In an agent system, overly permissive routing can lead to incorrect tool use, unintended prompt-context switching, or misapplication of this skill's instructions to unrelated tasks.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal