Back to skill

Security audit

tdd

Security checks across malware telemetry and agentic risk

Overview

This is a coherent TDD helper, but its broad triggers and forced first action could make an agent edit or run tests before the user has clearly asked for that workflow.

Install this only if you want a strict TDD workflow that may start by creating and running tests. Consider narrowing activation to explicit TDD or test-run requests, and require user confirmation before commits or broad test execution in sensitive repositories.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation guidance does not define clear boundaries for when the skill should and should not activate, despite advertising many broad trigger terms. In context, this is made more concerning by the skill's rigid instruction that invocation must immediately force a specific workflow, increasing the chance that unrelated requests are steered into unnecessary or disruptive test-driven steps.

Vague Triggers

Low
Confidence
84% confidence
Finding
The activation guidance does not define clear boundaries for when the skill should and should not activate, despite advertising many broad trigger terms. In context, this is made more concerning by the skill's rigid instruction that invocation must immediately force a specific workflow, increasing the chance that unrelated requests are steered into unnecessary or disruptive test-driven steps.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases in this skill are broad enough to match common requests like 'verify' or 'run tests', which can cause the skill to activate in contexts where the user did not explicitly request this workflow. Over-broad activation increases the chance of unintended command guidance, unnecessary repository inspection, or test-execution recommendations being injected into unrelated tasks.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.