Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only helper for unit-test coverage work, with some broad auto-invocation wording but no hidden execution, data access, persistence, or destructive behavior.

Installers should understand that this skill may be invoked automatically for broad testing or quality-related prompts; use explicit wording when you want unit-test coverage help, and review any generated code or test changes before applying them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentence is extremely broad and can match many ordinary testing-related requests, causing the skill to activate outside its intended scope. Overly broad activation increases the chance that the agent applies canned testing workflows where they are not appropriate, which can degrade routing quality and potentially override more relevant or safer skills.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The invocation guidance does not define clear trigger boundaries or exclusions, so the skill may be selected for a wide range of generic software-help requests. In an agent ecosystem, ambiguous routing rules can lead to unintended execution paths, reduced predictability, and abuse through prompt phrasing that forces the wrong skill to engage.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are generic enough to match normal requests about unit tests, test coverage, or practical workflows, which can cause the skill to activate when the user did not explicitly intend to invoke it. In an agent system, overly broad routing increases the chance of unintended behavior, prompt/context hijacking between skills, and reduced user control over which capability is used.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill description is broad enough to match many ordinary software requests, which can cause the skill to activate outside its intended scope. Over-broad activation increases the chance that this skill intercepts unrelated prompts and influences agent behavior in ways the user did not intend.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The trigger keywords are generic terms like testing, regression, and quality, which appear in many unrelated requests. Without stronger gating conditions, these triggers can cause accidental invocation and prompt-scope confusion, making agent behavior less predictable and easier to steer indirectly.

Vague Triggers

Low
Confidence
88% confidence
Finding
The example trigger uses a common conversational phrase that does not meaningfully constrain when the skill should be used. This normalizes activation from vague language and can encourage broad matching behavior across routine user requests.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description and use conditions are broad enough that it could activate for generic software or testing-related requests outside the intended scope. This can cause misrouting to the skill, producing irrelevant guidance or overriding a more appropriate skill, which is a real security and reliability concern in agent routing even without malicious content.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The keyword list includes very broad terms such as testing, regression, and quality without qualifiers, which can match many unrelated conversations. In an automated skill-selection environment, overly generic keywords increase accidental invocation and may steer the agent into an inappropriate workflow.

Vague Triggers

Low
Confidence
82% confidence
Finding
The example trigger phrases are highly generic and resemble ordinary user requests, making accidental activation more likely. While the direct impact is limited, ambiguous examples reinforce broad routing behavior and can contribute to persistent over-triggering of the skill.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The default prompt is extremely broad and maps to common development language such as software, tests, testing, analysis, workflow, and implementation support. In combination with agent routing, this can cause the skill to activate in many normal conversations where the user did not explicitly request it, increasing the chance of unintended prompt injection exposure, context leakage, or inappropriate tool influence.

Vague Triggers

Medium
Confidence
93% confidence
Finding
Enabling implicit invocation without well-defined trigger boundaries allows the skill to be auto-selected during unrelated or only loosely related requests. Because this skill is broadly described and oriented toward implementation support, unintended activation could expose user context to the skill and amplify any unsafe behavior or misrouting across a wide range of developer conversations.

Vague Triggers

High
Confidence
90% confidence
Finding
The trigger sentence is so broad and awkwardly templated that it can match ordinary user requests about needing help or a practical workflow, causing the skill to activate outside its intended scope. In an agent system, over-broad activation can misroute conversations, override more appropriate skills, and increase the chance that unrelated prompts receive testing-oriented guidance or automated actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.