Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only testing helper with broad auto-invocation wording, but no hidden execution, credential use, persistence, or unrelated data access.

Installers should be aware that this helper may activate for broad testing or quality requests. It is otherwise proportionate for a unit-test coverage workflow; review generated code changes and test commands as usual before applying them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentences are generic and templated enough that the skill may activate on broad, ordinary testing-related requests without clear user intent to invoke this specific workflow. In an agent ecosystem, ambiguous invocation increases the chance of unintended skill routing, which can cause the wrong instructions or outputs to be applied to user requests and weaken user control over tool selection.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger phrases are broad natural-language patterns that can match many ordinary requests about testing, coverage, or workflows, increasing the chance the skill is invoked when the user did not explicitly intend it. In an agent environment, unintended invocation can cause prompt-routing errors, irrelevant automation, or accidental disclosure of repository context to the wrong skill.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill description is broad enough to match many ordinary software-help requests, which can cause unintended invocation outside its narrowly intended use. Over-broad activation increases the chance that the agent applies this skill in contexts where its assumptions or workflow are not appropriate, leading to misrouting, lower-quality guidance, or accidental precedence over more suitable skills.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The keyword list contains vague terms like 'testing', 'regression', and 'quality' that overlap heavily with routine engineering conversations. This makes accidental triggering likely and can route unrelated requests into this skill, creating prompt-selection ambiguity and increasing the attack surface for skill misuse or instruction collision.

Vague Triggers

Low
Confidence
89% confidence
Finding
The example triggers use generic phrasing and do not clearly distinguish valid from invalid activation scenarios. Ambiguous examples reinforce over-triggering behavior and make it harder for orchestration logic or maintainers to understand the intended boundaries of the skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger keywords are broad and include generic terms like "testing" and "quality", which can cause the skill to activate for many unrelated requests. In an agent system, this can route users into the wrong workflow, producing irrelevant guidance and reducing trust or masking the correct skill.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The activation criteria in the description are overly broad and lack clear boundaries for when the skill should or should not be used. This increases the chance of false activation across general software or testing discussions, which can misroute tasks and create unsafe or low-quality automation decisions.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt is very broad and includes generic terms like software, data, testing, regression, workflow, artifact, checklist, analysis, and implementation support. In systems that support automatic or heuristic skill routing, this can cause the skill to trigger in many ordinary conversations, increasing the chance of unintended context capture, prompt interference, or misrouting of user requests.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without clear constraints allows the platform to auto-activate this skill based on loose semantic matches rather than explicit user intent. Because this skill advertises a broad testing and implementation-support scope, implicit activation can expand the attack surface for prompt collisions, unintended tool usage, or unauthorized exposure of user context to the skill.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger sentence is excessively broad and resembles ordinary user phrasing, which can cause the skill to activate in situations where the user did not explicitly intend to invoke it. In an agent system, this can lead to prompt-routing mistakes, unexpected instruction injection into unrelated tasks, or suppression of more appropriate skills.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.