Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward unit-test coverage helper with some broad activation wording, but no hidden execution, credential access, persistence, or destructive behavior.

Before installing, understand that this helper may be invoked for general testing or quality requests because its triggers are broad. It appears safe for local test-coverage assistance, but users who want precise routing should narrow the triggers or invoke it explicitly only when adding unit tests or analyzing coverage.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentences are broad enough that the skill may activate for generic testing or workflow requests without strong confirmation that the user specifically wants this capability. That can cause unintended invocation, increased prompt/context injection surface, and misrouting to this skill when a more appropriate or narrower skill should handle the request.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are broad enough to activate on generic requests about testing, workflows, or software/data, which can cause the skill to be invoked outside its intended scope. In an agent system, overly permissive activation increases the chance of context mismatch, unintended handling of user requests, and delegation to a skill that may produce irrelevant or misleading outputs.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description uses broad terms like 'software-and-data', 'testing', and 'analysis', which can cause the skill to activate for many ordinary requests outside its intended scope. Over-broad activation increases the chance of unintended routing, conflicting instructions, or inappropriate application of this skill in contexts where a more specific skill or direct response would be safer.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keyword list includes generic terms like 'software-and-data', 'testing', and 'quality' without boundaries or disambiguation. This makes accidental invocation likely and can let the skill intercept a wide range of normal development requests, reducing predictability and potentially surfacing irrelevant or lower-quality guidance.

Vague Triggers

Low
Confidence
84% confidence
Finding
The example trigger starts with the generic phrase 'Help me', which weakens trigger precision when combined with the already broad skill description. While not dangerous by itself, it contributes to accidental activation and reinforces ambiguous routing behavior.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger description is very broad and can cause the skill to activate for many generic software requests, not just requests specifically about improving unit tests or coverage. Over-broad activation increases the chance of inappropriate routing, context leakage between tasks, or the model following this workflow when a more suitable or safer skill should have been used.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The keyword list contains common technical terms like 'testing', 'regression', and 'quality' without qualifiers, which makes accidental invocation likely across unrelated development conversations. This can misroute user requests and cause the skill to steer outputs beyond its intended narrow function, reducing safety and predictability.

Vague Triggers

Low
Confidence
86% confidence
Finding
The example trigger phrases are underspecified and normalize very broad requests, teaching the orchestrator or user that almost any mention of practical workflow help should invoke this skill. While not directly exploitable as code execution, this weakens routing precision and can lead to inappropriate use in unrelated contexts.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill’s display text and default prompt are broadly phrased around common software testing needs, while implicit invocation is enabled. This can cause the agent to trigger in situations beyond the author’s intended scope, leading to over-broad delegation, prompt hijacking exposure, or unintended handling of unrelated code and data.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger sentence is so broad and unnatural that it can match ordinary user requests about unit tests, workflows, or implementation help far beyond a narrowly scoped invocation. This creates prompt-routing ambiguity and can cause the skill to activate unexpectedly, potentially overriding safer or more appropriate handlers and increasing the attack surface for prompt injection through routine conversation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.