Security audit
测试技术选型
Security checks for vulnerabilities and agentic risk
Overview
This is a guidance-only QA tool-selection skill with proportionate read and web access, and it does not show hidden installation, persistence, credential use, or destructive behavior.
Install this skill if you want structured QA testing tool selection guidance. Be aware it can direct an agent to read project files and fetch web information for research, and separately review the suggested full QA skill set before running its `npx skills add` command.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
