Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only helper for unit-test coverage work, with broad activation wording but no hidden execution, persistence, credential access, or destructive behavior.

Installers should be aware that this skill may activate on broad testing or quality-related requests; use it when you specifically want unit-test coverage planning or implementation help, and review generated code changes before applying them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger sentences are generic and templated enough that they could cause the skill to be invoked in situations beyond the author's intended scope. In an agent ecosystem, overly broad invocation criteria can lead to misrouting, unnecessary context exposure, or execution of the wrong workflow, even if the skill itself is not overtly dangerous.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description is broad enough to trigger on common software-help requests such as testing, regression, or implementation support, even when the user's need may not specifically be about improving unit-test coverage. Over-broad activation can cause the wrong skill to engage, leading to irrelevant guidance, context hijacking, or routing away from a more appropriate skill.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The keyword list contains high-collision terms like 'testing', 'regression', and 'quality' that are widely applicable across many unrelated tasks. In a skill-routing system, these vague triggers can cause frequent false activations, making the skill easier to invoke unintentionally and reducing trust in routing behavior.

Vague Triggers

Low
Confidence
88% confidence
Finding
The example triggers use generic formulations like 'help me' and 'I need a practical workflow' without clarifying what makes this skill uniquely applicable. This increases ambiguity for both users and automated matchers, reinforcing over-triggering behavior established elsewhere in the file.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description is extremely broad and can match many ordinary software/testing requests, which increases the chance of unintended invocation. Over-broad activation can route user queries into the wrong workflow, causing context confusion, reduced reliability, and possible propagation of irrelevant code/test changes in sensitive repositories.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The keyword list contains very common terms like 'testing', 'regression', and 'quality', which are likely to appear in routine technical conversations unrelated to this skill. This raises the risk of accidental triggering and workflow hijacking, especially in multi-skill environments where broad keywords can overshadow more appropriate, narrowly scoped skills.

Vague Triggers

Low
Confidence
87% confidence
Finding
The example trigger phrases are highly generic and demonstrate direct invocation for a broadly worded demand without showing limits or counterexamples. This trains routing systems or users toward overuse of the skill, which can increase accidental activation and reduce precision, though the impact is lower than an always-on keyword rule.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The default prompt contains a very broad natural-language activation phrase ('Use $unit-test-coverage-helper to help me...') tied to common software/testing terms. Because the skill allows implicit invocation, ordinary user requests about testing or coverage could unintentionally trigger this skill, causing prompt injection of skill instructions into unrelated conversations or unexpected tool routing.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger sentence is effectively a natural-language catchall ('Help me ...' / 'I need a practical workflow ...') around broad testing terms, which can cause this skill to activate on many ordinary software requests that were not meant for it. Over-broad activation increases the chance of prompt/skill misrouting, where the agent injects this workflow into unrelated contexts and may override a more appropriate or safer specialized skill.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.