Back to skill

Security audit

Qa

Security checks across malware telemetry and agentic risk

Overview

This QA skill is purpose-aligned, but it can use browser sessions, submit forms, edit code, and create git commits with too little scoping for automatic use.

Install only if you want an agent to actively test and change a web application. Use it on a clean feature branch, prefer staging or disposable test accounts, avoid production cookies or live destructive workflows, and review screenshots, reports, diffs, and commits before pushing or deploying.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad enough to match common conversational requests like 'does this work?' or 'feature is ready for testing,' which can cause the skill to activate unintentionally. Because this skill performs code changes and git commits, accidental invocation can lead to unrequested repository modifications and browser-driven actions without sufficiently explicit user consent.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill description advertises testing and bug fixing but does not clearly warn that it will modify source code and create git commits automatically. Users may invoke it expecting a diagnostic-only QA pass, while the skill can edit code, commit changes, and alter repository state, making this a meaningful consent and integrity risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.