Back to skill

Security audit

Agent Testcase Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed test-case template generator with Feishu document output, and its main issue is language/accessibility rather than unsafe behavior.

Before installing, confirm the listed Feishu knowledge base/wiki node is the intended workspace and avoid providing test requirements or internal system details you do not want stored there. Expect Chinese-format output unless you explicitly request another language.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The skill metadata and content strongly prescribe Chinese-language interaction/output without indicating that the agent should honor the user's preferred language. This can cause user-intent misalignment, reduce accessibility, and lead to incorrect or unusable outputs for users operating in other languages, especially in testing contexts where exact wording matters.

Static analysis

No suspicious patterns detected.