Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-only helper for unit test coverage workflows, with some overly broad activation wording but no hidden execution, credential access, persistence, or data exfiltration behavior.

Before installing, be aware that the skill may be invoked for broad software testing or quality requests. It is otherwise a low-risk helper: review its suggestions like any code-writing guidance and run proposed tests locally before accepting changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentence 'Help me Teams need repeatable help adding useful unit tests and raising test coverage for existing codebases.' is overly broad and resembles a common conversational phrase rather than a narrowly scoped activation condition. In agent-routing systems, broad triggers can cause unintended invocation of this skill in unrelated conversations, leading to misrouting, prompt-surface expansion, and reduced control over which instructions are applied.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger sentence 'I need a practical workflow for Teams need repeatable help adding useful unit tests and raising test coverage for existing codebases.' is ambiguous and generic, making it difficult to distinguish legitimate use from unrelated requests that mention workflows. This can cause accidental skill activation and broaden the attack surface by injecting this skill's instructions into contexts where they were not intended.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad enough that the skill could activate for vague requests about testing or software work that do not clearly intend to use this specific helper. In an agent environment, ambiguous activation can cause the wrong skill to run, leading to inappropriate guidance, scope confusion, or indirect prompt-routing abuse if an attacker deliberately crafts generic trigger text.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger keywords include very broad terms such as "testing" and "quality," which can match many unrelated software conversations and cause the skill to activate outside its intended scope. Unintended invocation can steer users into irrelevant workflows, override better-matched skills, or expose the system to prompt-routing abuse where generic phrasing is used to force this skill into contexts it was not designed for.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The example trigger sentences use broad everyday phrasing like "Help me" and "I need a practical workflow," which may teach downstream routing systems or authors to invoke the skill on weak signals. This increases the chance of accidental or adversarial activation in contexts only loosely related to unit testing, reducing routing precision and making skill selection easier to manipulate.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger keywords are broad enough that ordinary discussion of testing, regression, or quality could activate the skill when a more appropriate skill was intended. This can cause incorrect routing, unnecessary invocation, or confusing outputs, though it does not directly enable code execution or data exfiltration.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description defines applicability very broadly and does not clearly state exclusion criteria, increasing the chance of overbroad activation across many software-related requests. In an agent system, ambiguous routing can degrade reliability and may expose users to irrelevant or misleading automation, especially when multiple skills overlap.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The default prompt trigger phrase is broad and maps to common user requests around testing, coverage, and implementation help. Because implicit invocation is enabled, ordinary conversation about unit tests or software workflows could unintentionally activate this skill, causing prompt injection of the skill context or unexpected behavior without clear user intent.

Vague Triggers

High
Confidence
92% confidence
Finding
The trigger sentence is so broad and unnatural that it can match loosely related user requests and cause this skill to activate outside its intended scope. In an agent system, over-broad activation can misroute tasks, override more appropriate skills, and lead to irrelevant or low-quality outputs that may affect code or testing workflows.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.