简历撰写助手

Security checks across malware telemetry and agentic risk

Overview

The resume-customizing files look mostly normal, but the published metadata claims financial and purchase authority that does not fit this skill.

Install only if you can remove or ignore the unrelated financial/purchase capability tags. Use it with resumes, job descriptions, and output paths you intentionally provide, and review generated resumes for accuracy before sending them to employers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding
The skill explicitly instructs use of local file parsing and output generation scripts, and it also supports fetching job descriptions from URLs via the requests dependency, which implies file read, file write, and network access. However, the manifest declares no permissions or equivalent capability disclosures, creating a mismatch that can lead to over-privileged or non-transparent execution against sensitive resume data and arbitrary remote resources.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal