Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only unit-test coverage helper with some broad activation wording, but no hidden execution, credential handling, persistence, or unrelated data access.

Install this if you want an assistant workflow for adding tests and improving coverage. Be aware that its broad trigger wording may make it activate on general testing or quality requests, so users should explicitly state when they do or do not want this skill applied.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentence is written in very broad, natural help-seeking language, which increases the chance that the skill will activate on generic user requests rather than only when explicitly relevant. In an agent environment, over-broad routing can cause unintended context capture, incorrect tool/skill selection, and prompt-surface expansion, even if the skill itself is not overtly malicious.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The invocation guidance uses broad phrasing ('I need a practical workflow for...') that lacks clear boundaries for when the skill should or should not activate. This can lead to accidental invocation across unrelated tasks, reducing routing precision and potentially exposing users to irrelevant instructions or hidden skill behavior they did not explicitly request.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are generic and can activate on broad requests like testing, regression, or practical workflow needs without strong scoping constraints. In an agent ecosystem, this increases the chance of unintended invocation, context hijacking, or the skill being selected for requests outside its intended boundaries, which can lead to incorrect actions or overbroad access to code and project context.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill description is broad enough to activate on common software requests such as testing, regression, or implementation support, even when the user may not specifically want this skill. Over-broad activation increases the chance of unintended routing, causing the agent to apply this skill outside its intended scope and potentially override more appropriate skills or safer decision paths.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The keyword list contains highly generic terms like 'testing', 'regression', and 'quality' without qualifiers, which can match a wide range of unrelated requests. In an agentic system, these broad triggers can cause inappropriate skill invocation and reduce routing precision, creating operational and security risk through context misapplication.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The example trigger sentences use vague lead-ins like 'Help me' and 'I need a practical workflow' combined with repeated requirement text, which normalizes weak matching patterns. This can make the router treat generic user language as sufficient for activation, increasing the chance of accidental invocation in unrelated conversations.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger keywords are broad and overlap with common software-development conversations such as testing, regression, and quality. This can cause the skill to activate in loosely related contexts, leading to incorrect routing, irrelevant guidance, or reduced trust in the agent’s behavior, though it does not by itself enable code execution or data exfiltration.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description defines applicability very broadly, covering multiple generic domains and artifact types without clear exclusion criteria. In practice this increases the chance of over-invocation on unrelated requests, which can mis-handle user intent and make the assistant less predictable.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt uses very broad trigger language ('help me' plus a wide set of software/testing terms), which can cause the skill to be invoked in contexts the user did not clearly intend. Because implicit invocation is enabled, this increases the chance of accidental routing, over-collection of context, or the skill influencing unrelated coding tasks.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger sentence uses a very broad everyday phrase ('Help me ...'), which can cause the skill to activate in contexts far beyond its intended scope. Over-broad activation increases the chance of prompt hijacking, misrouting, or accidental invocation when a user is asking for general help rather than unit-test coverage assistance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.