Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a plain guidance workflow for adding unit tests and improving coverage, with no hidden code execution or sensitive access.

Installers should understand that this skill may activate for broad testing or quality requests, but its content is guidance-only and does not itself add privileged tools, persistent processes, or credential access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentences are extremely generic and can match a wide range of normal software requests involving tests, regression, or workflows. Overly broad activation increases the chance this skill is invoked when a different, more appropriate skill or safer narrower workflow should handle the request, leading to misrouting and unintended behavior.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are generic natural-language requests that closely match ordinary user asks for testing help, making accidental invocation likely. In an agent environment, this can cause the skill to activate outside intended scope, override more appropriate skills, or introduce unreviewed workflow behavior into unrelated conversations.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description includes very broad activation terms such as 'software-and-data', 'testing', and 'analysis', which can cause the skill to trigger on many ordinary engineering requests outside its intended scope. Over-broad routing increases the chance of inappropriate invocation, context bleed, and misleading guidance being applied where a more specialized or safer skill should handle the request.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The keyword trigger list contains vague terms like 'testing', 'regression', and 'quality' without boundaries, making accidental activation likely. In a skill-routing system, such generic triggers can hijack unrelated requests and cause the agent to apply the wrong workflow or expose unnecessary repository-focused behavior.

Vague Triggers

Low
Confidence
80% confidence
Finding
The example trigger sentences use generic constructions like 'Help me' and 'I need a practical workflow' combined with repeated requirement text, which are ambiguous for activation and may normalize loose matching behavior. While less severe than broad keywords, ambiguous exemplars can encourage over-triggering in systems that learn or pattern-match from examples.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger keywords include broad, common terms such as testing, regression, and quality, which can overlap with many ordinary software conversations. This can cause the skill to activate outside its intended scope, leading to inappropriate context injection or unintended workflow steering in unrelated tasks.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example trigger phrases are highly generic and effectively encourage activation on broad requests without clear qualification. This increases the chance of false activation, which can reduce system reliability and cause the agent to apply this skill in contexts where it is not appropriate.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt contains broad, generic language such as helping with unit tests, test coverage, testing, regression, workflows, and implementation support, which can match many ordinary developer requests and cause unintended implicit invocation. Because implicit invocation is enabled, this increases the chance the skill activates in contexts the user did not explicitly request, creating prompt-surface expansion and possible misrouting of user tasks.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence is so generic that it can match ordinary user phrasing rather than an explicit request to invoke this specific skill. That creates a routing risk where the agent may activate this skill in unintended contexts, leading to irrelevant or lower-quality responses and making prompt-routing behavior easier to manipulate.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.