Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward unit-test and coverage helper with broad activation wording but no hidden execution, credential use, persistence, or destructive behavior.

This skill is reasonable to install for coding workflows, especially when you want help adding tests or raising coverage. Be aware that its broad trigger terms and implicit invocation setting may cause it to activate for general testing or quality discussions, so users should confirm it is the intended helper when working in sensitive repositories.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad enough to match ordinary testing-related requests, which can cause the skill to activate in situations where the user did not explicitly request it. In an agent-routing system, this increases the chance of inappropriate tool/skill invocation, mis-scoped assistance, or prompt-surface expansion from unrelated conversations.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are very broad and closely match ordinary requests about software, testing, and workflows, which can cause the skill to activate in many unrelated or only partially related contexts. Over-broad activation increases the chance of misrouting user requests, unnecessary skill invocation, and unintended influence over conversations that did not explicitly ask for this specific helper.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description uses broad activation terms such as software-and-data, testing, and regression, which can match a wide range of ordinary developer requests unrelated to the specific unit-test-coverage purpose. Over-broad triggers increase the chance of inappropriate skill activation, causing the agent to apply the wrong workflow or disclose irrelevant guidance in contexts where a narrower skill should have been selected.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The example trigger begins with the generic phrase "Help me," which is so common that it can spuriously match many unrelated user requests. In an agent-routing system, such generic invocation examples can bias selection toward this skill, leading to misrouting, unintended execution of its workflow, and reduced reliability of downstream security or task-specific controls.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description uses very broad trigger categories such as software-and-data, unit tests, test coverage, testing, and regression without clear boundaries or exclusion criteria. This can cause the skill to activate for many unrelated software requests, leading to unintended routing, lower-quality assistance, and possible interference with more appropriate skills.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The keyword trigger list contains common technical terms like testing, regression, and quality that appear in many unrelated prompts. In a skill-selection system, this increases accidental invocation and prompt hijacking of normal requests, which can misroute user intent and degrade system behavior.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt is broad and maps to common software-testing language, which increases the chance of accidental invocation during ordinary conversations about unit tests, regression, or coverage. In systems that auto-route based on prompt matching, this can cause unintended skill activation, unexpected behavior, or unnecessary exposure of project context to this skill.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without strong activation constraints allows the skill to be triggered automatically from broadly matching requests. Combined with this skill's general testing-related scope, that increases the risk of over-triggering, context leakage, and user confusion about when the skill is acting versus when the base assistant is responding.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence is so generic that it can match ordinary user phrasing unrelated to an explicit request to invoke this skill. In an agent system, overly broad activation increases the chance of unintended routing, causing the skill to engage on prompts where its assumptions or workflows do not fit, which can mis-handle user intent or suppress safer/more appropriate skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.