Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This is a text-only helper for unit-test coverage work, with some overly broad activation wording but no hidden execution, credential access, persistence, or data exfiltration behavior.

Install this if you want a reusable assistant workflow for improving unit tests and coverage. Be aware that its broad trigger wording may make it activate for general testing or quality requests, so explicitly name a different skill or workflow when your task is not about unit-test coverage.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentences are generic enough that normal user requests about testing or practical workflows could invoke this skill unintentionally. Over-broad activation can cause the wrong skill to handle requests, leading to irrelevant guidance, context bleed, or accidental execution of testing-oriented workflows where they were not intended.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad enough to match many ordinary software-help requests, which can cause the skill to activate outside its intended scope. In an agent system, overbroad invocation increases the chance of prompt hijacking through unintended routing, unnecessary exposure of repository context, or the skill influencing tasks that did not require it.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger keywords are broad and overlap with common software-development requests, which can cause the skill to activate in situations where the user did not explicitly intend to invoke it. While this is not directly a code-execution issue, unintended invocation can lead to context hijacking, confusing routing, or the skill influencing responses outside its narrowly intended scope.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The example trigger phrases use generic natural-language wording that resembles ordinary user requests, making accidental activation more likely. In agent systems, ambiguous activation boundaries can cause the wrong skill to take control, reducing predictability and potentially exposing unrelated tasks to this skill's instructions.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description and usage conditions are broad enough to overlap with many ordinary software-development requests, increasing the chance the skill activates when the user did not specifically want unit-test coverage assistance. Mis-triggering is a security and reliability concern because it can steer the agent into an unintended workflow, override more appropriate skills, or cause unnecessary code/test modifications in unrelated contexts.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The keyword list includes generic terms such as testing, regression, and quality without scope constraints, which makes accidental activation likely across a wide range of normal engineering conversations. In a skill-routing system, overly broad triggers can degrade isolation between skills and cause the wrong instructions or artifacts to be applied to sensitive repositories or development tasks.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The default prompt is phrased in broad, everyday language around common software tasks like unit tests, coverage, testing, and implementation support. That makes accidental or overly eager invocation more likely in unrelated coding conversations, which can route user context into this skill without sufficiently clear boundaries.

Vague Triggers

Medium
Confidence
92% confidence
Finding
Enabling implicit invocation without defined activation boundaries allows the platform to trigger the skill based on loose relevance matching rather than explicit user intent. In a skill that offers workflow, analysis, and implementation support, this increases the risk of unintended activation, unnecessary context exposure, and confusing or unauthorized task steering.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger sentence is broad enough to match ordinary user phrasing rather than a clearly scoped invocation, which can cause this skill to activate in contexts where the user did not explicitly request unit-test coverage help. In agent systems, overbroad activation creates routing confusion and can lead to inappropriate access to context, misleading outputs, or interference with other more relevant skills.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.