Back to skill

Security audit

Unit Test Coverage Helper

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only helper for unit-test coverage work, with broad activation wording but no hidden execution, persistence, credential use, or data exfiltration behavior.

Before installing, be aware that the skill may activate on broad software quality or testing requests. It is appropriate if you want a general unit-test coverage workflow helper, but explicit invocation is safer when you only want it used for coverage-improvement tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrases are generic help-seeking sentences that can match many ordinary user requests, causing the skill to activate outside its intended scope. Overly broad activation increases the chance of inappropriate instruction injection into unrelated conversations and can override more suitable, narrower skills.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases are very broad and can activate on generic testing or software requests without strong boundaries, which increases the chance the skill is invoked in contexts the user did not clearly intend. In an agent ecosystem, overbroad routing can cause inappropriate handling of requests, unexpected file/code analysis behavior, or accidental exposure of repository context to the wrong skill path.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description includes very broad activation terms such as 'software-and-data', 'testing', and 'analysis', which can cause the skill to trigger in many unrelated software conversations. Over-broad routing increases the chance that the wrong skill handles a request, leading to confused behavior, prompt-scope hijacking, or lower-quality outputs in contexts where more specific skills or baseline handling should apply.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The keyword list contains generic terms like 'testing', 'regression', and 'quality' that commonly appear in routine engineering discussions without implying a need for this specific skill. This creates a routing collision risk where the skill may activate unexpectedly and influence responses outside its intended domain.

Vague Triggers

Low
Confidence
84% confidence
Finding
The example trigger starts with the broad phrase 'Help me', which is common in normal user requests and can reinforce overly permissive triggering behavior. While the rest of the example is more specific, including generic lead-in language in trigger examples encourages accidental matches and weakens skill-boundary precision.

Vague Triggers

Medium
Confidence
92% confidence
Finding
技能描述的触发条件覆盖了非常常见的测试相关话题,如 unit tests、test coverage、testing、regression,且没有提供明确的边界或排除条件。这会导致技能在大量普通开发对话中被误触发,造成上下文劫持、错误路由或让不相关请求被该技能主导处理。

Vague Triggers

Medium
Confidence
95% confidence
Finding
关键词列表包含 software-and-data、unit tests、testing、quality 等高度泛化词汇,这些词在大量无关请求中都会出现。攻击者或普通用户都可能轻易触发该技能,导致技能选择失准,并可能压制更适合的专用技能或基础对话流程。

Vague Triggers

Low
Confidence
84% confidence
Finding
示例触发句只是重复需求文本或使用模糊的 'practical workflow' 表述,没有展示清晰的激活边界。这样的示例会强化宽泛匹配策略,使实现者或路由器更难区分何时应激活该技能,增加误用概率。

Vague Triggers

Medium
Confidence
90% confidence
Finding
The default prompt contains a broad natural-language trigger phrase ('help me' plus generic testing terms) that can cause unintended or implicit invocation in ordinary user requests about software, testing, or coverage. Because implicit invocation is enabled, benign user conversations may unexpectedly activate this skill, increasing the chance of prompt-routing abuse, unauthorized context exposure, or execution of workflows the user did not explicitly request.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger sentence is broad enough to match ordinary user phrasing, which can cause this skill to activate in situations beyond its intended scope. Over-broad activation increases the chance of unintended routing, context hijacking, or the skill being invoked on unrelated requests where it may produce misleading testing guidance or interfere with safer, more appropriate handling.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.