Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only helper for unit-test and coverage workflows, with some broad auto-invocation wording but no hidden execution, persistence, or data-access behavior.

Installers should know this skill may activate for broad testing or quality-related requests. Review or narrow its trigger wording if precise routing matters, but the inspected artifacts do not show hidden commands, credential use, persistence, or destructive behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is phrased as a generic help request and can overlap with ordinary user language, making accidental or overly broad activation more likely. In agent systems, ambiguous activation expands the skill's execution surface and can cause the skill to run in contexts where it was not explicitly intended, which may interfere with routing or override more appropriate skills.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation guidance lists broad keywords and sample triggers but does not define clear boundaries, prerequisites, or exclusions for when the skill should activate. This creates routing ambiguity and increases the chance that unrelated software-help requests will invoke the skill, which can lead to unintended behavior, poor task delegation, or prompt-surface expansion in multi-skill environments.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad enough to match many ordinary software-testing requests, which can cause the skill to activate outside narrowly intended contexts. In an agent ecosystem, overbroad activation can lead to incorrect routing, unexpected behavior, or unreviewed instructions being applied when a user simply asks for general help with tests or quality.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description uses broad trigger terms like "software-and-data," "testing," and "analysis," which can cause the skill to activate for many unrelated requests. Overly broad routing increases the chance of unintended invocation, confusing task selection and potentially causing this skill to override a more appropriate or safer specialized skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The example trigger phrases are written in very general language (for example, "Help me" / "I need a practical workflow") wrapped around the requirement text, which may match loosely related user requests. This broadens invocation beyond the intended domain and can lead to accidental skill selection, reducing reliability of the agent's routing behavior.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill description is broadly phrased around common software-testing terms and generic support tasks, which can cause the skill to activate for routine conversations that are only loosely related. This is not a code-execution issue, but it can lead to misrouting, over-application of the skill, and reduced reliability of agent behavior.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keyword list includes highly generic terms like 'testing', 'regression', and 'quality' without guardrails, making accidental invocation more likely across many unrelated software requests. In an agent system, overbroad triggers can override more appropriate skills, create confused task selection, and increase the attack surface for prompt-routing abuse through keyword stuffing.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt uses a very broad, everyday trigger phrase around common software tasks like unit tests, testing, and implementation support. This can cause the skill to be invoked in contexts far beyond the author's likely intent, increasing the chance of unintended prompt injection exposure, irrelevant activation, or the skill influencing unrelated developer workflows.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Implicit invocation is enabled without clear trigger constraints, allowing the skill to activate automatically based on broad matching rather than explicit user selection. In a developer-assistance context, this increases the attack surface for unintended routing, overreach into unrelated coding tasks, and abuse through crafted prompts that cause the system to invoke the skill when it should not.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is so broadly phrased that it can match normal user requests unrelated to a deliberate invocation of this skill. That creates unintended activation risk, causing the agent to apply this skill in the wrong contexts and potentially override more appropriate routing or produce irrelevant code/testing guidance.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The examples define positive triggers but do not establish clear boundaries for when the skill should not activate. This ambiguity increases the chance of false-positive routing, especially because the examples include generic helper phrasing that could capture everyday requests and steer the system into an unintended workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.