Back to skill

Security audit

测试干系人沟通

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward QA communication template skill with limited read/search tool access and clear warnings about sensitive test data.

Review QA inputs before use and avoid providing real production customer data, payment details, identity numbers, phone numbers, or unredacted screenshots. The optional full skill-set install should be considered separately before running any npx command.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.