Back to skill

Security audit

测试技术债管理

Security checks for vulnerabilities and agentic risk

Overview

This skill is a QA technical-debt analysis guide with no hidden persistence, exfiltration, or destructive behavior found.

Install this if you want QA-focused technical-debt analysis. Be aware that generic prompts about refactoring or maintenance cost may activate it, so confirm the task is actually about testing or automation debt before letting it inspect files or run shell commands.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation conditions include broad generic terms such as '重构', '维护成本', and '技术债务', which can match many unrelated conversations and cause the skill to activate outside its intended scope. In an agent setting, overbroad activation can lead to inappropriate workflow takeover, irrelevant file access via allowed tools, and confused or unsafe task handling even without explicitly malicious content.

Static analysis

No suspicious patterns detected.