51mee Resume Diagnose

Security checks across malware telemetry and agentic risk

Overview

This skill analyzes uploaded resumes with a language model and returns feedback; the main consideration is privacy, not hidden or unsafe behavior.

Install only if you are comfortable having uploaded resume contents analyzed by a model. Consider redacting unnecessary personal details before use; no executable code, credential use, persistence, or hidden behavior was observed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the system to read uploaded resume files, extract their text, and send that content to a language model without any explicit privacy notice, consent checkpoint, or data-handling constraint. Resumes commonly contain sensitive personal data such as phone numbers, email addresses, employment history, education, and location details, so silent transmission to a model can expose users to unintended data disclosure and compliance risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal