Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only helper for adding unit tests and improving coverage, with a minor risk that its broad triggers could activate it too often.

Install this if you want repeatable help adding or improving unit tests. Be aware that its broad trigger terms may cause it to activate for general testing or quality requests; explicit invocation is safer when you want predictable routing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentence is highly generic and can match many ordinary user requests about testing or practical help, causing the skill to activate outside its intended scope. Over-broad activation increases the chance that the agent will inappropriately route unrelated requests to this skill, which can degrade safety controls and produce irrelevant or misleading outputs.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation description uses a broad request pattern that lacks clear boundaries, making accidental or excessive skill invocation likely. In an agentic environment, ambiguous routing logic can expose users to incorrect workflows, context leakage across tasks, or bypass of more appropriate specialized skills.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad enough to match common requests about testing and workflows, which can cause the skill to activate outside narrowly intended contexts. Over-broad activation increases the chance of incorrect routing, prompt hijacking of unrelated requests, or unreviewed skill behavior being injected into normal conversations.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger keywords are broad enough to match many ordinary software requests, which can cause this skill to activate outside its intended scope. Over-broad activation is dangerous because it can override more appropriate skills or inject irrelevant testing workflows into unrelated tasks, reducing reliability and potentially causing unsafe or incorrect assistance in mixed-context requests.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The example trigger phrases use generic everyday wording like 'Help me' and 'I need a practical workflow', making the activation pattern susceptible to matching common requests that are not specifically about unit testing. This increases accidental invocation risk, which can misroute user requests and weaken system prompt/skill selection hygiene.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger keywords are broad and overlap with common software discussions, which can cause the skill to activate outside its intended scope. Mis-triggering is a security-relevant quality issue because it can route users into an unrelated workflow, increasing the chance of inappropriate guidance, unintended data handling, or prompt-surface expansion.

Vague Triggers

Low
Confidence
82% confidence
Finding
The example trigger phrase uses highly generic wording ('I need a practical workflow') without enough domain scoping, which encourages ambiguous invocation. This can lead to accidental activation in unrelated tasks, reducing predictability and making it easier for adversarial or noisy prompts to steer the agent into the skill unexpectedly.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt contains a very broad activation phrase tied to common topics like software, unit tests, testing, and implementation support. In systems that allow implicit invocation, this can cause the skill to trigger in ordinary conversations unrelated to an explicit request for this tool, increasing the chance of unintended prompt injection exposure or unexpected tool behavior.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentence uses a very broad everyday phrase ('Help me') tied to automatic skill activation, which can cause the skill to engage in contexts far beyond unit testing or coverage work. Overly broad routing increases prompt/scope confusion risk and may cause the agent to apply this skill when the user did not actually request testing assistance, leading to incorrect actions or disclosure of unrelated context to the skill workflow.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.