Back to skill

Security audit

测试估算

Security checks for vulnerabilities and agentic risk

Overview

This skill is a QA test-estimation template with limited read-only tool access and no evidence of hidden execution, persistence, or data exfiltration.

Before installing, users should know this skill is intended for QA test-effort estimation and may activate on broad scheduling language. If it triggers in a general project-management conversation, confirm whether a QA testing estimate is actually wanted. The inspected artifact does not show hidden execution, persistence, or external data sharing.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The invocation phrases are very broad and include common planning terms like '排期', '资源规划', '工期', and '多久测完', which can match ordinary project-management conversations outside the user's intent to use this skill. This increases the chance of unintended activation, causing the agent to shift into a specialized estimation workflow when the user may have wanted general discussion or a different planning task.

Static analysis

No suspicious patterns detected.