Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This is a simple unit-test coverage guidance skill with broad auto-invocation wording, but no hidden execution, credential access, persistence, or unrelated behavior.

Install this if you want an agent helper for unit-test coverage workflows. Be aware it may be selected for fairly broad testing or quality-related prompts, so invoke a more specific skill by name when you need different QA, debugging, or implementation behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentences are broad enough to match many ordinary testing-related requests, which can cause this skill to activate when the user did not explicitly ask for it. In an agent ecosystem, over-broad routing can lead to unintended instruction injection from the skill, incorrect task handling, or displacement of a more appropriate skill.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad and generic, including common terms like 'unit tests', 'test coverage', and 'testing', plus natural-language prompts that could match many ordinary requests. This increases the chance of unintended invocation, which can route users into this skill when they did not explicitly request it and may cause inappropriate actions or responses in broader agent workflows.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is broad enough to activate on many ordinary software requests, not just narrowly scoped unit-test coverage tasks. Overbroad routing can cause the wrong skill to be invoked, leading to irrelevant guidance, accidental context capture, or overshadowing of more appropriate skills.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The keyword list contains highly generic terms like 'testing' and 'quality' that are likely to appear in unrelated user requests. This increases unintended invocation risk and can misroute user sessions into this skill when another specialized skill would be more appropriate.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The example triggers use natural, everyday phrasing that overlaps with common user language, which can train or encourage overmatching behavior. In a skill-routing system, such collisions can degrade reliability and cause this skill to intercept routine requests outside its intended niche.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger keywords are broad and overlap with common software-development conversations, which can cause the skill to activate in contexts where the user did not specifically ask for unit-test coverage help. In an agent system, this can route requests incorrectly, produce irrelevant actions, and increase the chance that the skill influences tasks outside its intended scope.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description defines activation conditions so broadly that many ordinary development requests could match, especially because it includes general categories like software-and-data, testing, and regression without precise scope limits. Overbroad activation is dangerous in multi-skill environments because it can cause unintended invocation, response hijacking, and reduced trust in routing decisions.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt contains very broad natural-language trigger terms such as software, testing, regression, workflow, artifact, and analysis support. Because these concepts commonly appear in ordinary user requests, the skill may be invoked unintentionally, causing prompt-routing or capability confusion and exposing users to behavior they did not explicitly request.

Vague Triggers

Medium
Confidence
93% confidence
Finding
Enabling implicit invocation without clear trigger constraints allows the platform to auto-select this skill based on loosely related user language. In combination with the broad prompt, this increases the chance of unintended activation, misrouting sensitive requests, and unreviewed skill execution in contexts where the user did not mean to use this helper.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is written so broadly that normal user requests about unit tests or practical workflows could invoke this skill unintentionally. Overbroad activation can cause misrouting, unnecessary disclosure of repository details to the wrong skill context, and unreliable agent behavior, especially in multi-skill systems where precise dispatch boundaries matter.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger descriptions define broad keywords and sample sentences but do not specify exclusion criteria, boundary conditions, or when this skill should not be selected. In an agent environment, that ambiguity increases the chance of accidental activation and prompt-routing conflicts with other software, QA, or coding-assistance skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.