Back to skill

Security audit

Qa Shift Left

Security checks across malware telemetry and agentic risk

Overview

This appears to be a QA guidance skill with only minor routing ambiguity, not evidence of harmful behavior.

Safe to install if you want help with shift-left QA practices. If a request is just general requirements analysis, code review, or test automation design, make sure your agent uses this skill only when that workflow is actually relevant.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The activation trigger is broadly phrased and can match generic QA discussions such as early testing, requirements review, or development-stage testing without a clear user intent to invoke this skill. In an agent environment, this can cause unintended routing, leading the assistant to apply the wrong workflow, ignore user preferences, or overshadow more appropriate skills.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The description says the skill auto-triggers for broad situations like early project involvement or development-stage testing guidance, which are common across many QA tasks. This increases the chance of over-activation and misclassification, potentially steering conversations into this skill when the user actually needs requirements analysis, code review, or automation architecture support.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal