Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only helper for unit test coverage work, with broad activation wording but no hidden execution, credential access, persistence, or destructive behavior.

Install this if you want an agent workflow for improving unit tests and coverage. Be aware it may activate on fairly broad testing-related requests, so use explicit instructions when you want a different testing workflow or no code changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are broad and include generic requests such as asking for a practical workflow or help with unit tests and testing, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance of misrouting user requests, unintended invocation, or prompt-surface expansion where unrelated tasks are handled under this skill's instructions.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are very generic and include natural language requests that could match many ordinary conversations about testing, coverage, or workflows. This increases the chance the skill is invoked unintentionally, which can route users into an unexpected workflow, create confusing behavior, or cause an agent to prioritize this skill when a narrower or safer skill would be more appropriate.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description is broad enough to match common software-help requests beyond its intended niche, which can cause the agent to invoke this skill in inappropriate contexts. Over-broad routing increases the chance of prompt/skill confusion, where a generic request is handled by a specialized workflow that may make unsafe assumptions or expose unnecessary files, code, or analysis steps.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Using the everyday phrase 'Help me' as part of an example trigger makes the invocation pattern too permissive and likely to overlap with ordinary user requests. In agent ecosystems, this can lead to accidental activation, misrouting, and application of this skill's instructions where they do not belong, reducing reliability and potentially broadening access to code-analysis behaviors unnecessarily.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt uses a very broad natural-language invocation phrase ('Use $unit-test-coverage-helper to help me...') tied to generic topics like software, testing, and implementation support. When combined with implicit invocation, this can cause the skill to trigger on common user requests unintentionally, expanding the skill's reach beyond clear user intent and increasing the chance of prompt/context injection through automatic routing.

Vague Triggers

Medium
Confidence
96% confidence
Finding
Enabling allow_implicit_invocation without clear trigger constraints allows the platform to invoke this skill automatically for broad classes of testing or software questions. Because the skill description and prompt are generic, unintended invocation becomes more likely, which can lead to scope creep, user confusion, and increased exposure to adversarial content routed into the skill without an explicit opt-in.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentence is so generic that normal user requests about testing or software help could invoke this skill unintentionally. Over-broad activation increases the chance the agent applies the wrong workflow, causing prompt-routing confusion, unexpected behavior, or exposure of repository-specific guidance in contexts where it was not intended.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The invocation section lacks clear boundaries for when the skill should and should not run, which makes accidental or overly aggressive triggering likely. In an agent system, ambiguous routing can lead to misuse of the skill, irrelevant actions, and increased attack surface because common language can be used to steer behavior indirectly.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.