Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This is a plain unit-test coverage helper with broad trigger wording but no hidden code, credential access, persistence, or destructive behavior.

This skill is reasonable to install for help with unit tests and coverage. Be aware that its broad keywords may cause it to appear for general testing or quality discussions; if precise routing matters, narrow the triggers or disable implicit invocation. Review any suggested code edits or test commands before applying them, as with any coding assistant workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentence is broad enough to match many ordinary software-help requests, which can cause this skill to activate when the user did not explicitly ask for it. Over-broad activation increases the chance of inappropriate context capture, unnecessary instruction injection, or interference with more suitable skills, especially in multi-skill agent environments.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The invocation guidance lacks precise boundaries for when the skill should and should not run, creating ambiguity that can lead to accidental or excessive triggering. In an agent system, ambiguous routing can cause this skill to override user intent, compete with unrelated skills, or introduce unnecessary workflow steps into general programming requests.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad and generic enough that the skill may activate for many ordinary software-testing requests without strong user intent. In an agentic system, this can cause unintended invocation, context capture, or workflow steering, which is a real security and reliability concern even though the file itself does not contain code execution or privilege-escalation behavior.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description is broad enough to match many ordinary software requests, which can cause unintended invocation outside the narrow unit-testing use case. Over-broad activation increases the chance that the agent applies this skill in contexts where its assumptions, workflow, or file access expectations are inappropriate, leading to misrouting and expanded prompt surface.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The keyword list includes vague, high-frequency terms such as 'testing' and 'quality' without boundaries, making accidental triggering likely. In an agent environment, broad keywords can route unrelated conversations into this skill, exposing users to irrelevant instructions and increasing the attack surface for prompt-selection abuse.

Vague Triggers

Low
Confidence
84% confidence
Finding
The example triggers are written in generic natural language that closely resembles normal user requests, so they may collide with benign conversation and cause over-selection. While this is less severe than executable or data-exfiltration behavior, it still degrades routing precision and can steer the assistant into unnecessary or overly prescriptive workflows.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description and activation guidance are broad enough that many ordinary software/help requests could match unintentionally. Over-broad routing can cause this skill to activate outside its intended scope, leading to irrelevant or lower-quality responses and potentially overriding a more appropriate, safer, or domain-specific skill.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The keyword list includes highly generic terms like testing, regression, and quality, which are common across many unrelated engineering conversations. This increases the chance of accidental invocation, causing misrouting and unnecessary exposure of the skill's instructions in contexts where another workflow should handle the request.

Vague Triggers

Low
Confidence
88% confidence
Finding
The example trigger phrases use very general wording such as asking for practical workflow help, which can normalize matching on broad user language instead of precise testing-related intent. This makes false activations more likely and weakens the boundary between this skill and adjacent software-assistance skills.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The default prompt trigger phrase is broad and maps to common requests about software, testing, and implementation support, which increases the chance of unintended or implicit invocation. Because implicit invocation is enabled, normal user language about tests or coverage could activate this skill unexpectedly and route user context into the skill without a clearly intentional selection.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is overly broad and can match ordinary user language, causing the skill to activate in contexts where the user did not explicitly intend to invoke it. Over-broad activation increases the attack surface for prompt-routing mistakes, accidental tool use, and unintended influence over unrelated conversations.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation description uses a reusable generic phrase that lacks clear boundaries, so the skill may be selected for many common requests outside its intended scope. This can lead to inappropriate routing, user confusion, and increased likelihood that the skill influences tasks it was not designed to handle.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.