Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward unit-test coverage helper, with a minor routing concern from broad trigger wording but no hidden or disproportionate behavior.

Before installing, be aware that this skill may activate for broad testing or quality-related requests. It appears safe for its stated purpose, but more specific trigger wording would reduce accidental invocation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentences are broad natural-language phrases that closely resemble ordinary user requests, which can cause the skill to activate unintentionally when a user is merely discussing testing or asking for general help. In an agent ecosystem, this increases the chance of prompt-routing mistakes, unexpected behavior, or unwanted execution of this skill instead of a more appropriate tool.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match ordinary software-help requests, which can cause this skill to activate unexpectedly outside narrowly intended testing contexts. In an agent ecosystem, overbroad routing increases the chance that the skill handles unrelated prompts, potentially displacing safer or more appropriate skills and amplifying any risky guidance contained in the skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description uses broad activation terms such as 'software-and-data', 'testing', and 'regression', which can match many ordinary developer requests unrelated to this specific skill. Overbroad triggers increase the chance of unintended invocation, causing the agent to route users into an irrelevant workflow and potentially override better-scoped skills or default behavior.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The example trigger begins with the highly generic phrase 'Help me', which is common across a wide range of harmless user requests. This makes accidental activation more likely because simple help-seeking phrasing may be interpreted as a match even when the user did not intend to invoke this skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger keywords include very broad terms such as "testing" and "quality", which commonly appear in ordinary software discussions. In an agent routing context, this can cause accidental invocation of the skill for unrelated requests, leading to misrouting, unnecessary context exposure, or inappropriate automated actions based on the wrong workflow.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The example trigger phrases begin with highly generic language like "Help me" and "I need a practical workflow", which does not clearly distinguish this skill from many other development-assistance requests. This weak boundary increases the chance that the orchestration layer will match the skill too aggressively and route unrelated tasks into it.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation while advertising a very broad trigger surface across common software-development terms like testing, regression, and implementation support. This can cause the agent to auto-select the skill in many ordinary conversations, increasing the chance of unintended prompt injection exposure, context leakage into the skill, or execution of workflows the user did not explicitly request.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger sentence is phrased with broad, everyday language ('Help me', 'I need a practical workflow') that can cause the skill to activate in many unrelated conversations. Over-broad activation increases the chance of unintended routing, context confusion, or prompt-shadowing where this skill influences tasks outside its intended scope.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.