Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward unit-test coverage helper with broad activation wording but no hidden execution, credential access, persistence, or destructive behavior.

Before installing, be aware that this skill may be invoked for general testing or quality requests because its trigger wording is broad. It appears safe for its intended use, but users should still review proposed code changes and test commands before applying them to a repository.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentence is broad enough to match ordinary user requests for testing help, which can cause the skill to activate outside clearly intended contexts. In an agent system, overbroad activation can hijack unrelated conversations, suppress more appropriate skills, or let a loosely scoped skill influence outputs more often than intended.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The invocation guidance lacks precise activation boundaries, so the skill may be selected for general software-help requests rather than only for unit-test-coverage assistance. This ambiguity increases the chance of unintended routing and prompt-scope expansion, which is a real security/control issue in multi-skill agent environments even without overtly malicious content.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases are broad enough to match ordinary requests about testing, coverage, and practical workflows, which can cause this skill to activate when the user did not explicitly intend it. In an agent environment, overly broad routing increases the chance of unintended skill invocation and can steer requests into this skill's workflow instead of a more appropriate or safer handler.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description uses very broad activation language such as 'software-and-data' and generic testing-related terms, which can cause the skill to be invoked for many ordinary software requests outside its narrow purpose. Overbroad routing increases the chance of incorrect skill selection, unintended instruction injection into unrelated tasks, and reduced trust in agent behavior.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords are too generic to safely distinguish intended invocations because terms like 'testing', 'regression', and 'quality' commonly appear in many software conversations. This can lead to accidental activation and inappropriate application of the skill's workflow in contexts where a different skill or no skill should be used.

Vague Triggers

Low
Confidence
90% confidence
Finding
The example trigger begins with the very general phrase 'Help me', which provides almost no constraint on when the skill should activate. In a routing system that relies on examples, this broad phrasing can bias the model toward invoking the skill for unrelated help requests, causing misrouting rather than direct code-execution harm.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation description is broad and loosely bounded, covering generic software-and-data and testing-related requests without clear exclusions. This can cause the skill to trigger in contexts where it is not the best match, increasing the chance of irrelevant guidance, instruction hijacking precedence issues, or unintended handling of sensitive development tasks.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The keyword list includes highly generic terms such as testing, regression, and quality, which are likely to match many unrelated conversations. Overbroad keyword activation can lead to accidental invocation of the skill, causing mis-scoped assistance and raising the risk that other more appropriate safeguards or specialized skills are bypassed.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill metadata uses broad, common trigger terms such as software-and-data, unit tests, test coverage, testing, regression, workflow, artifact, checklist, analysis, and implementation support, while implicit invocation is enabled. This can cause the agent to invoke the skill in many ordinary development conversations where the user did not explicitly request it, increasing the chance of inappropriate context access, overreach, or prompt-surface expansion.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence is overly broad and can match ordinary user phrasing, causing this skill to activate in contexts where the user did not explicitly request it. In a routing or tool-selection system, that can lead to inappropriate invocation, noisy responses, or accidental overshadowing of more suitable skills, which becomes a security and reliability concern if the skill influences downstream actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.