Back to skill

Security audit

测试技术选型

Security checks for vulnerabilities and agentic risk

Overview

This is a guidance-only QA tool-selection skill with proportionate read and web access, and it does not show hidden installation, persistence, credential use, or destructive behavior.

Install this skill if you want structured QA testing tool selection guidance. Be aware it can direct an agent to read project files and fetch web information for research, and separately review the suggested full QA skill set before running its `npx skills add` command.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.