Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only unit-test coverage helper with no executable code, though its auto-activation wording is broader than ideal.

Before installing, be aware that this skill may auto-activate for broad testing or quality prompts. It is otherwise a straightforward local unit-test workflow helper; users who want tighter control should invoke it explicitly or narrow its triggers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad enough to activate on common testing-related requests without strong scoping, which can cause the wrong skill to run in contexts only loosely related to unit-test coverage. In an agent system, ambiguous activation increases the chance of unintended instruction routing, prompt collision, or misuse of this skill when a more specific or safer workflow should apply.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger phrases are generic and likely to match ordinary requests about testing, workflows, or implementation support, causing the skill to activate outside narrowly intended contexts. In an agent system, this can lead to prompt-routing collisions, unintended invocation, and reduced user control over which skill handles a request.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The manifest description includes broad invocation terms such as 'software-and-data', 'testing', and 'analysis', which can cause the skill to activate for many general engineering requests outside the narrow task of improving unit tests and coverage. Over-broad routing increases the chance that this skill intercepts unrelated prompts and produces mis-scoped guidance, reducing reliability and potentially bypassing better-matched skills or controls.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger keyword list contains vague terms like 'software-and-data', 'testing', 'regression', and 'quality' that are common across many unrelated tasks. Such generic triggers can cause accidental activation, creating prompt-routing confusion and allowing this skill to be selected in contexts it was not designed to handle.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The example trigger sentences use broad, everyday phrasing like 'Help me' and 'I need a practical workflow', which do not establish clear boundaries for when the skill should or should not activate. Ambiguous examples can train or encourage over-selection of the skill for generic assistance requests, increasing the risk of incorrect routing and irrelevant output.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description is extremely broad and includes generic software-testing concepts plus a long natural-language demand statement, which can cause the skill to activate in many ordinary development conversations. Over-broad triggering increases the chance of unintended routing, causing the assistant to follow this skill when a more appropriate or safer specialized workflow should apply.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The keyword list contains highly generic terms like 'testing', 'regression', and 'quality', which are common in normal conversation and likely to overlap with unrelated requests. This can lead to accidental invocation of the skill, reducing routing precision and potentially steering users into an irrelevant workflow or exposing broader prompt-surface for misuse.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The default prompt uses very broad, common-language phrasing such as software, data, unit tests, testing, regression, workflow, checklist, analysis, and implementation support. In combination with agent routing, this can cause the skill to be invoked for loosely related requests, exposing users to unintended prompt injection surface or causing the agent to act outside the user's precise intent.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Enabling implicit invocation without a tightly scoped trigger policy allows this skill to activate automatically based on ambiguous user language. Because this skill is broadly described and test-related requests are common, unintended invocation is plausible and can expand the attack surface for misrouting, overreach, or prompt-confusion behaviors.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger sentence is so broad and unnatural that it can match ordinary user requests about unit tests, test coverage, or practical workflows far beyond a narrowly scoped invocation. This increases the chance of accidental skill activation, causing the agent to apply this skill in unintended contexts and potentially override more appropriate safeguards or routing logic.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.