Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only helper for adding unit tests and improving coverage; its main issue is broad auto-activation wording, not hidden or destructive behavior.

Install this only if you want a helper that may activate for general testing or quality requests. Expect it to guide test and coverage work in local repositories; review any generated code changes as you normally would.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentences are broad enough to match ordinary help-seeking requests about testing and workflows, which can cause the skill to activate in contexts where the user did not explicitly request it. In an agentic system, overbroad routing can override more appropriate skills, increase unintended instruction exposure, and create prompt-scope confusion.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are very broad and include generic terms like 'testing' and templated prompts that could cause the skill to activate for many loosely related requests. Over-broad activation can misroute user tasks, increase unintended invocation, and make it easier for a skill to intercept requests outside its intended scope.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger keywords are broad and generic, especially terms like 'testing', 'regression', and 'quality', which can match many unrelated requests. This can cause unintended skill invocation, leading the agent to apply this skill in contexts where it is not the best fit and potentially crowding out more appropriate skills or workflows.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The example trigger uses the vague phrase 'Help me', which is extremely common and weakly scoped. In systems that rely on fuzzy matching or example-based routing, this increases the risk of accidental activation for unrelated user prompts, reducing routing precision and possibly exposing irrelevant instructions or outputs.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description and usage conditions are broad enough to overlap with many ordinary software requests, which can cause the skill to activate when the user did not specifically need unit-test or coverage assistance. In an agent environment, overbroad triggering can misroute tasks, produce irrelevant code or process changes, and increase the chance that the skill influences requests outside its intended scope.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The keyword list includes very broad terms like testing, regression, and quality without contextual constraints, making accidental invocation likely during routine engineering conversations. This is dangerous because an agent may select this skill in unrelated contexts, causing scope confusion, unnecessary actions, or incorrect guidance applied to non-testing tasks.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt uses very broad natural-language triggers like 'unit tests', 'test coverage', 'testing', and 'analysis', which can cause the skill to be selected in situations beyond the user's explicit intent. In an implicitly invokable agent system, this increases the risk of over-triggering, context hijacking, or unintended delegation to this skill during ordinary software discussions.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without tightly defined scope allows the system to auto-select this skill based on loosely related conversation content. Because this skill targets common software-engineering topics, it may activate frequently and unexpectedly, potentially causing misrouting of user requests, unnecessary exposure of repository context, or interference with more appropriate skills.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is so generic that it can match ordinary user phrasing rather than a narrowly scoped request for this specific skill. That increases the chance of unintended skill activation, causing the agent to apply the wrong workflow, produce irrelevant artifacts, or override a more appropriate skill selection path.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger definitions lack boundaries, disambiguation rules, and negative examples, so the routing logic may invoke this skill for loosely related software requests. In an agent system, ambiguous activation criteria are dangerous because they can misroute tasks, degrade reliability, and create opportunities for prompt/skill confusion across overlapping capabilities.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.