Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This is a transparent unit-test workflow helper with some broad activation wording but no hidden, persistent, credential-seeking, or destructive behavior.

Before installing, be aware that the skill may be selected for broad testing or code-quality requests because of its trigger wording. Review any generated tests or code changes as you normally would, but the inspected package itself is documentation-only and does not contain executable setup, persistence, credential access, or destructive instructions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are extremely generic ('Help me...', 'I need a practical workflow...') and can match ordinary user requests unrelated to this specific skill. That broad activation surface can cause unintended routing or opportunistic invocation, which may override more appropriate skills and expose users to irrelevant or lower-quality guidance.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad enough to match many ordinary software help requests, which can cause the skill to activate when the user did not explicitly intend to use it. In an agent system, overbroad activation can lead to inappropriate context injection, workflow hijacking, or unexpected actions being taken under the skill's guidance.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description uses very broad routing language such as 'software-and-data', 'testing', and 'analysis', which can match many ordinary development requests beyond unit-test coverage work. Over-broad triggers can cause incorrect skill activation, leading the agent to apply the wrong workflow or expose unrelated repository context unnecessarily during handling of loosely related prompts.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example trigger begins with the everyday phrase 'Help me', which is too generic and increases the chance that normal user requests are incorrectly matched to this skill. This can degrade routing integrity by invoking the skill in contexts where it is not appropriate, potentially causing confused-deputy behavior or irrelevant code/test modifications.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger description is overly broad, covering generic terms like software-and-data, testing, regression, and quality that commonly appear in many unrelated requests. This can cause the skill to activate outside its intended scope, leading to inappropriate routing, irrelevant guidance, or accidental overshadowing of more suitable skills.

Vague Triggers

Low
Confidence
84% confidence
Finding
The trigger examples are repetitive and broad, but do not define clear boundaries or non-trigger cases. Without negative examples, an agent may match on vague wording and invoke this skill for loosely related testing requests, reducing precision and potentially interfering with safer or more relevant workflows.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The default prompt uses a very broad invocation phrase tied to common software-testing requests, which increases the chance that the skill is triggered in situations beyond the user's explicit intent. In an agent ecosystem, this can cause unnecessary access to the skill's instructions and outputs, creating prompt-scope creep and making routing easier to manipulate or misfire.

Vague Triggers

Medium
Confidence
93% confidence
Finding
Enabling implicit invocation without strict activation constraints allows the skill to be auto-selected based on loosely related user requests. This broadens the attack surface for unintended tool routing, increases the likelihood of inappropriate activation, and can expose the system to prompt injection or context-misapplication through unnecessary skill engagement.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentence is broad enough to match ordinary user phrasing, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance that unrelated requests are routed through this skill, creating prompt-selection confusion and enabling indirect misuse of the skill in contexts where its assumptions do not hold.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.