Back to skill

Security audit

Unit Test Coverage Helper

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill for guiding unit-test and coverage work, with no executable code, persistence, credential handling, or hidden data flow.

Before installing, be aware that the skill may activate on broad testing or quality-related requests. It appears safe from a security perspective, but users who want tighter routing should narrow the trigger language to explicit unit-test, coverage, or regression-test requests.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad enough that the skill may activate for generic requests about testing or workflows without strong scoping constraints. This can cause unintended routing or over-invocation of the skill, which is a real security/governance concern in agent systems because it expands the skill’s influence beyond the user’s precise intent, though the content here is not itself privileged or directly harmful.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are broad enough that the skill could activate for generic testing or software requests without clear boundaries, causing the agent to apply this workflow in contexts the user did not intend. In an agent ecosystem, overbroad routing can expose repository details, test artifacts, or code-modification behavior in unrelated conversations, making this a real scope-control weakness even though the README itself is not executable code.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description uses very broad activation terms like 'software-and-data', 'testing', and 'implementation support', which can match many ordinary development requests beyond the narrow unit-test-coverage use case. This increases the chance the skill is invoked unexpectedly, causing prompt-scope overreach and potentially steering unrelated coding tasks through this skill's instructions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger examples use vague everyday phrasing such as 'Help me...' and 'I need a practical workflow...' without clear activation boundaries, making accidental or overly broad invocation more likely. In an agent environment, ambiguous triggers can route general software requests into this skill even when the user did not specifically ask for unit-test or coverage assistance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description defines a very broad activation scope spanning generic software and testing terms, which can cause the skill to trigger in conversations that do not actually need this specialized workflow. Over-broad triggering can override more appropriate skills, cause unintended instruction injection into unrelated tasks, and reduce reliability of agent behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The keyword list includes highly generic terms like testing, regression, and quality, which are common in ordinary technical discussions and likely to produce accidental activation. In an agent system, this increases the chance of contextually inappropriate skill routing, which can mislead the workflow, expose irrelevant instructions, or interfere with safer or more suitable skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The default prompt is broad and generic enough that the skill may be invoked in situations only loosely related to unit testing or coverage work. Combined with allow_implicit_invocation=true, this increases the chance of unintended activation, which can cause unnecessary tool use, prompt-context pollution, or execution of a less appropriate workflow than the user intended.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger sentence is so broad and unnatural that it can match generic user requests unrelated to the intended skill, causing the agent to invoke this skill in inappropriate contexts. Misrouting is especially risky for a code-focused skill because it may steer conversations into generating test/code artifacts when the user only mentioned overlapping terms, reducing reliability and potentially exposing repository-specific guidance where it was not intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Although this is a zh-CN README, key user-facing content such as the demand description, usage description, keywords, and trigger phrases is written in English. This imposes a language expectation without explicitly offering users a language choice or documenting the bilingual behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

该技能文件为中文本地化版本(SKILL.zh-CN.md),但内容中未见任何说明用户可选择其他语言或该语言限制的适用范围。按组织语言/地区策略,若技能默认强制特定语言而无用户选择或明确理由,属于自然语言政策风险。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.