Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only unit test coverage helper with some overly broad activation wording but no hidden execution, persistence, or data-handling behavior.

Before installing, be aware that this skill may be selected for general testing or quality requests because its triggers are broad. It is best used when you specifically want help adding unit tests, finding coverage gaps, or creating regression-test workflows.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are extremely generic and can match a wide range of ordinary requests about testing, workflows, or implementation support, causing the skill to activate outside its intended scope. Over-broad activation increases the chance of prompt/skill hijacking, incorrect tool routing, or unintended disclosure of repository context to a skill that was not explicitly requested.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are broad enough to match ordinary user requests about testing, unit tests, or workflows, which can cause the skill to activate when the user did not explicitly intend to use it. In an agent ecosystem, overbroad activation can route conversations into the wrong skill, increasing the chance of unintended behavior or prompt-scope interference even though this README itself contains no direct code-execution payload.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description uses broad activation language such as 'software-and-data' and general testing-related terms, which can cause the skill to trigger on many routine development requests outside its narrow intended purpose. Over-broad routing is dangerous because it can misapply the skill in unrelated contexts, leading to incorrect delegation, prompt-surface expansion, or unintended handling of user requests.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example trigger starts with the vague phrase 'Help me', which is common in ordinary user messages and does not meaningfully constrain when the skill should activate. This increases the chance of accidental invocation or overmatching, especially in systems that rely on example phrases for routing behavior.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill’s activation description is very broad and overlaps with common software-development requests such as testing, regression, and practical workflow help. This can cause the skill to be invoked in situations beyond its intended scope, increasing the chance of irrelevant guidance, prompt-surface expansion, or unintended handling of unrelated coding tasks.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keywords are generic terms like 'testing', 'regression', and 'quality', which are commonly present in many normal development conversations. Without disambiguation or exclusion rules, the router may invoke this skill too often, creating overbroad delegation and increasing the risk of inappropriate context capture or user confusion.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The default prompt and description use broad, generic phrasing that can cause the platform to invoke this skill for a wide range of software/testing requests without clear boundaries. In an agent ecosystem, overly broad routing increases the chance the skill is selected in unintended contexts, which can lead to incorrect handling, prompt-surface expansion, or interference with more appropriate skills.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without defined activation criteria allows the orchestrator to auto-select this skill based on loose semantic similarity rather than precise conditions. That broadens the attack surface and can cause the skill to activate on adjacent development requests where it may receive sensitive code or influence outputs unexpectedly.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrase is broad enough to match ordinary user language, which can cause the skill to activate in contexts beyond its intended scope. In an agent system, over-broad activation can steer unrelated conversations into this skill's workflow, leading to incorrect actions, prompt hijacking surface expansion, and reduced reliability of routing decisions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.