Back to skill

Security audit

Unit Test Coverage Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a simple unit-test assistance skill with overly broad auto-invocation keywords but no hidden code, credential access, persistence, or destructive behavior.

Before installing, consider narrowing or disabling implicit invocation because common words may trigger the skill when you did not intend it. From a security standpoint, the artifact appears proportionate for unit-test support and does not add privileged runtime behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The explicit keyword list contains highly generic single-word triggers like 'add', 'unit', 'tests', 'level', and 'type', which are likely to appear in many normal conversations. In an agent routing system, this materially increases the chance of false activation, causing misrouting, context confusion, and possibly execution of this skill in situations unrelated to unit testing.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger terms in the metadata are extremely broad (add, unit, tests, labels) and are not scoped to a specific intent or phrasing. This can cause the skill to activate during unrelated conversations, which may steer the agent into irrelevant behavior, override a more appropriate skill, or create unintended disclosure of workflow content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger sentence uses very generic terms around 'add', 'unit', and 'tests', which can cause the skill to activate for unrelated requests that merely mention those common words. In an agentic system, unintended activation can route user requests into the wrong workflow, causing confusing guidance or inappropriate actions, even though this skill appears informational rather than overtly dangerous.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad enough to match ordinary help requests such as asking for practical workflow support or generic unit-test help, which can cause the skill to activate outside a clearly intentional invocation. In an agent system, over-broad activation can misroute user requests, cause unintended behavior, and increase the chance that a user is steered into this skill when they did not explicitly choose it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file descriptions explicitly label the main skill specification as English and this README as Chinese, but there is no statement that users can choose their preferred language or that the locale split is required for a region-specific purpose. This can conflict with language/locale policy expectations when a skill appears to prescribe language variants without opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description includes broad activation language such as 'general-help', 'add', 'unit', and 'tests', which are common terms in many unrelated requests. This can cause unintended invocation of the skill, leading the agent to apply the wrong workflow or expose irrelevant guidance in contexts where the user did not actually request unit-test support.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

该技能文件整体以中文呈现,文件名也表明为 zh-CN 版本,但内容未说明这是可选语言版本,也未告知用户可以选择其他语言。按规则,若技能强制特定语言而没有用户选择或明确合理的区域限定,属于自然语言策略问题。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The keyword list under the trigger section lacks boundaries, priority rules, or examples of non-matching cases, so common words can match outside the intended workflow. In an agentic environment, ambiguous activation logic increases the risk of accidental invocation and incorrect task routing, which can degrade safety and reliability.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The default prompt and description use very broad phrasing such as 'help me Add Unit Tests' and the metadata says to use the skill for 'general-help' and implementation support, which creates a loose trigger surface. In combination with implicit invocation, this can cause the skill to activate for routine development conversations where the user did not clearly request this helper, increasing prompt-scope confusion and unintended delegation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Enabling allow_implicit_invocation without additional context constraints allows the skill to be auto-invoked during loosely related conversations. Because this skill is framed broadly around practical workflow, checklist, analysis, and implementation support, unintended activation could steer agent behavior, expose unrelated context to the skill, or cause actions to be taken under the wrong capability.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill's activation signals include very generic keywords such as 'general-help', 'add', 'unit', and 'tests', which can match many unrelated user requests and cause the skill to trigger outside its intended scope. Over-broad invocation increases the chance of inappropriate routing, prompt interference with other skills, and accidental exposure of users to instructions that are irrelevant or lower quality for the task at hand.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger sentence 'Help me Add Unit Tests' is broad natural language that closely resembles ordinary user phrasing, so it may activate in many routine conversations where the user is not actually asking to invoke this specific skill. This ambiguity can lead to unintended skill selection and reduced reliability of task routing, though the content of this skill is operationally low risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.