Back to skill

Security audit

Unit Test Coverage Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only helper for unit-test coverage work, with no code execution or persistence, though its activation wording is broader than ideal.

Reasonable to install if you want a unit-test coverage workflow helper. Be aware it may activate on broad testing or quality-related prompts because implicit invocation is enabled and the trigger keywords are not very narrow.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger sentence is broad enough to match common user phrasing, which can cause the skill to activate outside its intended scope. In an agent system, over-broad activation can misroute requests, override more appropriate skills, and create opportunities for prompt-surface expansion through accidental invocation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger sentence starts with highly generic conversational phrasing ('Help me') and then appends the full requirement text, making activation boundaries weak and potentially causing the skill to trigger on ordinary user requests that merely resemble the requirement. In an agent system, overly broad trigger patterns can lead to unintended invocation, context hijacking, or misrouting of requests, especially when users ask generally for help with software tasks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This trigger pattern ('I need a practical workflow for ...') is broad and maps to common natural-language requests without a strong boundary separating normal conversation from intentional skill activation. Such ambiguity increases the chance of accidental or adversarial activation, which can cause the agent to select this skill inappropriately and interfere with correct task routing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad enough to activate on common software/testing requests, which can cause the wrong skill to be invoked without clear user intent. In an agent system, overbroad activation expands the skill’s influence and can lead to misrouting, unintended prompt injection surface area, or inappropriate handling of requests that only loosely match testing or coverage needs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description uses very broad activation terms such as 'software-and-data', 'testing', and 'implementation support', which can match many ordinary development requests unrelated to this specific capability. Over-broad routing increases the chance of unintended invocation, causing the agent to apply the wrong workflow, override a more appropriate skill, or expose users to unnecessary automated actions in unrelated contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The listed trigger keywords are generic terms commonly found in normal software conversations, including 'testing', 'regression', and 'quality'. If the skill-selection system relies on these keywords, the skill may activate for many unrelated prompts, increasing misrouting risk and making agent behavior less predictable.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger list includes very broad keywords such as "testing", "regression", and "quality", which can match many routine software conversations outside the skill's intended scope. Over-broad activation can cause the agent to invoke this skill in unrelated contexts, leading to irrelevant guidance, context hijacking, or accidental override of a more appropriate skill or safety policy.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The default prompt is phrased so broadly that it can match common user requests about software, testing, regression, workflows, or implementation support, increasing the chance the skill is invoked when the user did not explicitly intend it. Over-broad routing can expose unrelated conversations or code context to this skill and cause unintended actions or guidance in sensitive development workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Enabling implicit invocation without tight trigger constraints allows the platform to auto-route ordinary developer conversations to this skill based on ambiguous language. In a code-assistance context, that can unnecessarily grant the skill access to repository details, source snippets, or testing-related requests beyond the user's intent, increasing the risk of prompt-scope expansion and unintended processing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger descriptions do not clearly define when the skill should or should not activate, leaving activation scope ambiguous. This increases the chance of unintended routing and makes the system easier to manipulate with loosely related prompts that mention generic testing or workflow language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The file is named as a Simplified Chinese README, but key user-facing content such as the demand statement remains in English. This creates a language-policy inconsistency and may effectively force English for part of the experience without user opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example trigger sentence starts with a broad everyday request form ('Help me ...'), which can normalize invocation on vague user phrasing instead of clearly scoped testing requests. While lower impact than the keyword issue, it still contributes to accidental activation and weakens skill-boundary precision.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.