Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only unit-test coverage helper with broad activation wording but no hidden execution, credential access, persistence, or unrelated behavior.

Installers should be aware that this skill may be auto-selected for broad testing or quality requests. It is best used when you explicitly want help adding unit tests, improving coverage, or planning regression checks for an existing codebase.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence is phrased as a broad natural-language request ('Help me ...') that could match ordinary user intent without clearly requiring explicit skill invocation. In agent systems that auto-select skills from conversational text, this ambiguity can cause unintended activation, leading to unnecessary context capture or execution of this skill when the user did not specifically request it.

Vague Triggers

Medium
Confidence
89% confidence
Finding
Framing activation as a generic need statement ('I need a practical workflow for ...') makes the skill easier to trigger from normal discussion rather than deliberate selection. In orchestrated assistant environments, ambiguous matching increases the chance of false-positive routing and weakens separation between ordinary conversation and privileged skill behavior.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad enough to activate on common software-testing requests, which can cause unintended skill invocation and route users into this skill when they did not explicitly ask for it. In an agent ecosystem, overbroad activation increases the chance of misrouting, irrelevant automation, and accidental application of the skill to contexts outside its intended scope.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger description is broad enough to activate on many ordinary software requests, not just narrowly scoped unit-test coverage tasks. Over-broad routing can cause the agent to invoke this skill in unrelated contexts, leading to inappropriate guidance, reduced trust, and possible masking of more suitable or safer skills.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The example trigger phrases use highly generic language such as 'Help me' and 'I need a practical workflow,' which can match many unrelated requests when combined with broad trigger logic. This increases the chance of accidental skill activation and misclassification, especially in multi-skill environments where routing precision matters.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description is broad and covers common software-testing requests without strong boundary conditions, which can cause the agent to invoke this skill in situations where a more specific skill would be appropriate. This is dangerous because over-broad routing can produce unintended behavior, reduce predictability, and increase the chance that the skill acts on loosely related prompts.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger keywords include generic terms like testing, regression, and quality, which are common in many unrelated conversations. This raises the risk of accidental activation, causing the skill to intercept prompts outside its intended scope and potentially override more suitable workflows.

Vague Triggers

Low
Confidence
84% confidence
Finding
The example trigger phrases only show positive matches and do not define near-miss or excluded cases, making invocation boundaries ambiguous. This can lead to inconsistent routing and unnecessary skill activation when user intent is only loosely related to test coverage support.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The default prompt uses broad, everyday terms like software, unit tests, testing, regression, workflow, and implementation support, which can match many normal developer requests and cause the skill to be invoked when the user did not explicitly intend it. Unintended invocation can inject this skill's instructions or behavior into unrelated conversations, creating prompt-routing confusion and increasing the chance of overreach or interference with other skills.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without tight activation constraints allows the system to auto-select this skill based on loose semantic matches rather than clear user intent. In practice, this increases the attack surface for accidental or adversarial routing, where the skill may activate in contexts it should not, potentially affecting outputs, tool use, or downstream decision-making.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence 'Help me Teams need repeatable help adding useful unit tests and raising test coverage for existing codebases' is broad and awkwardly templated, making it likely to match ordinary user requests about testing rather than an explicit invocation. In agent routing systems, overly broad activation phrases can cause unintended skill selection, creating prompt-scope confusion and increasing the chance that this skill is invoked in contexts it was not meant to handle.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.