Back to skill

Security audit

Qa Test Leadership

Security checks across malware telemetry and agentic risk

Overview

This is a Chinese-language QA management guidance skill with no executable code, mutation behavior, persistence, or credential handling.

Install this if you want Chinese-language guidance for QA team leadership, performance reviews, and test hiring. Be aware it may activate on broad management terms, so users may need to invoke a different skill manually for non-testing management topics.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation trigger list includes very broad phrases such as “目标” and generic management terms that can easily appear in unrelated conversations. This can cause the skill to auto-trigger outside its intended test-leadership scope, leading to context hijacking, irrelevant guidance, or interference with a more appropriate skill.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The skill is authored entirely in Chinese and its trigger phrasing assumes Chinese-language interaction, without indicating fallback behavior or user language choice. In multilingual environments this can cause misrouting, user confusion, or inaccessible output, though it is not a direct code-execution or data-exfiltration risk.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal