Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only helper for unit-test coverage work, with no hidden execution or data access, though its automatic activation wording is broad.

Before installing, understand that this skill may be selected for broad testing or quality-related requests. It appears safe as a unit-test coverage helper, but users who want tighter control should prefer explicit invocation or narrower trigger wording.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are broad and template-like, which can cause the skill to activate for loosely related requests rather than explicit user intent. In an agent setting, ambiguous activation increases the chance of unintended instruction injection into unrelated workflows, creating scope confusion and potentially influencing outputs when the user did not clearly opt into this skill.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are very broad and include natural-language requests such as 'Help me...' and 'I need a practical workflow...', which can cause the skill to activate for generic conversations rather than clearly scoped testing tasks. In an agent setting, overly broad invocation language increases the chance of inappropriate routing, unintended execution, or prompt-surface expansion where unrelated user input is treated as a request to use the skill.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill description is broad enough to match many ordinary software requests, including general testing or quality discussions that may not actually need this specific skill. Overly broad activation increases the chance of unintended routing, which can cause the agent to apply the wrong workflow or expose users to unnecessary instructions in unrelated contexts.

Vague Triggers

Medium
Confidence
98% confidence
Finding
The keyword list includes highly ambiguous terms such as 'testing', 'regression', and 'quality', which are common across many software conversations and not specific to unit-test coverage work. This can cause accidental invocation and misclassification of user intent, making the skill easier to trigger outside its intended scope.

Vague Triggers

Low
Confidence
91% confidence
Finding
The example trigger phrases use generic helper language like 'Help me' and 'I need a practical workflow', which encourages activation from everyday requests without meaningful constraints. While not directly harmful, these examples reinforce loose routing behavior and broaden unintended skill use.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger conditions are broad and ambiguous, including generic terms like 'testing' and 'quality' plus example invocations that can match many unrelated requests. This can cause the skill to activate outside its intended scope, leading to incorrect routing, irrelevant guidance, or unintended interception of user tasks that should be handled by other skills.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The default prompt trigger is unusually broad and includes generic phrases like helping with unit tests and test coverage, which are common in normal developer conversation. Because implicit invocation is enabled, this can cause the skill to activate in contexts the user did not clearly intend, increasing the chance of prompt-context hijacking, unwanted routing, or over-collection of code/context into the skill.

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger sentence is so generic that it can match ordinary user phrasing and invoke the skill outside its intended scope. Overbroad activation increases the chance of unintended routing, prompt interference, or misuse of the skill in contexts where its assumptions and outputs are not appropriate.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.