Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-only helper for unit test coverage work, with a routing-quality concern but no hidden execution, persistence, credential use, or destructive behavior.

Before installing, be aware that this skill may be invoked for broad testing or quality-related requests because implicit invocation is enabled and the trigger terms are loose. It appears safe for test-coverage help, but users who want precise routing should narrow the triggers or invoke it explicitly only for unit-test and coverage tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentence is overly generic ('Help me ...', 'I need a practical workflow ...') and can match ordinary user requests that were not intended to invoke this specific skill. In an agent system, broad activation phrases can cause unintended routing, making the assistant apply this skill in irrelevant contexts and potentially override more appropriate safety or domain-specific handling.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are generic enough to match ordinary user requests about testing and practical workflows, which can cause the skill to activate outside its intended scope. Over-broad activation is dangerous because it can hijack unrelated conversations, suppress more appropriate skills, or cause the agent to apply this workflow in contexts where it lacks the right constraints or domain fit.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description and use conditions are broad enough to match many ordinary software requests, which can cause unintended activation outside the narrow unit-test-coverage use case. Over-broad routing is dangerous because it can override more appropriate skills, produce irrelevant guidance, and increase the chance that user context is handled by the wrong workflow.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords include ambiguous high-frequency terms like "testing," "regression," and "quality," which are likely to collide with many unrelated requests. This creates skill-routing risk: the agent may invoke this skill for broad QA or engineering discussions where its workflow is not appropriate, reducing reliability and potentially suppressing safer or more specialized handling.

Vague Triggers

Low
Confidence
81% confidence
Finding
The example triggers use very general phrasing and repeat the requirement text without clarifying when the skill should or should not activate. Vague examples reinforce loose matching behavior and make accidental invocation more likely, though the impact is lower than the keyword list because examples are typically secondary routing signals.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation description is overly broad and lacks clear boundaries, covering generic software-and-data and testing-related requests without strong gating conditions. This can cause the skill to trigger in unrelated contexts, leading to inappropriate instruction injection into conversations and reducing routing integrity, even though the content itself is not overtly malicious.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The keyword list contains broad, high-frequency terms such as testing, regression, and quality without contextual qualifiers. In an agent-routing system, such generic keywords can over-match many benign conversations, causing unintended skill activation and potentially displacing more appropriate skills or responses.

Vague Triggers

Low
Confidence
86% confidence
Finding
The example trigger uses the generic phrase 'Help me', which overlaps heavily with ordinary user language and may bias matching systems toward accidental activation. While lower severity than the other findings, it still weakens trigger precision and can increase false activations in normal interactions.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt contains a very broad activation phrase covering generic topics like software, unit tests, testing, regression, workflows, and implementation support. In combination with agent routing, this can cause the skill to be invoked for ordinary requests that were not intended to use it, increasing the chance of prompt hijacking, unnecessary data exposure to the skill, or user confusion about which agent is acting.

Vague Triggers

Medium
Confidence
94% confidence
Finding
Implicit invocation is enabled even though the manifest does not define strict trigger constraints, so the platform may auto-route many common engineering requests into this skill. Because the skill domain is broad and commonly discussed, this raises the likelihood of unintended activation and over-collection of user context, especially in mixed-task conversations involving source code or internal development details.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger sentence begins with an overly broad everyday phrase ('Help me'), which can cause the skill to activate on many unrelated user requests. In an agent-routing context, broad triggers increase the chance of accidental invocation, irrelevant instruction injection into conversations, and confused delegation that may override more appropriate specialized skills.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.