Back to skill

Security audit

测试用例设计

Security checks for vulnerabilities and agentic risk

Overview

This skill is a read-only QA test-case design guide with no hidden execution, persistence, or data-handling behavior.

Installers should treat this as a QA formatting and coverage-assistance skill. Provide requirements or prior analysis outputs for best results, and be aware that its broad trigger wording may activate for adjacent QA review requests.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger condition lists broad phrases such as requests for test case design, review, coverage, templates, and formatting guidance without clear exclusion criteria. In an agent system, this can cause the skill to activate for adjacent or partially related requests, leading to inappropriate workflow steering, confusion, or lower-quality outputs when prerequisite analysis has not actually been completed.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The automatic activation section enumerates example requests but does not define boundaries or disambiguation rules, so the skill may be selected for vague prompts like 'check these cases' or 'what scenarios are missing' even when another skill is more appropriate. This is risky in a multi-skill agent because overbroad auto-routing can suppress better-matched skills and produce incomplete or mis-scoped outputs.

Static analysis

No suspicious patterns detected.