Back to skill

Security audit

Agent Regression Testing

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Chinese-language regression testing/reporting helper that writes reports to a disclosed Feishu document location.

Before installing, confirm that writing regression plans, defect verification records, and release recommendations to the listed Feishu knowledge base is appropriate for your team. Do not include credentials, customer data, production secrets, or confidential incident details unless that Feishu space is approved for them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language invocation phrases and operational description are presented in Chinese only, which effectively constrains use to a specific language. The file does not offer user opt-in for language selection or explain that the skill is intentionally limited to a Chinese-language environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is configured to write regression artifacts to Feishu documents, but the user-facing description does not disclose that potentially sensitive test data, defect details, environment information, or release-readiness conclusions may be sent to an external document platform. This creates a real data-handling and consent problem because users may provide internal QA or production-adjacent information without realizing it will be persisted outside the immediate chat context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description is entirely in Chinese, which may indicate the skill is intended to operate or be presented in a fixed language without offering user choice. Under the policy, forcing a specific language without opt-in or justification is a natural-language locale concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.