Cover Letter Drafter

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward local cover-letter generator with only a user-directed optional file write to watch for.

Install only if you are comfortable running a small local Python script. If using --output, choose a trusted workspace path and a new filename to avoid accidental overwrite, and avoid saving sensitive manuscript or application details in shared directories.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill documents file-writing behavior (`--output`, output JSON file path) but does not declare corresponding permissions or constraints, which creates a transparency and governance gap around filesystem access. In a tool that may handle personal, academic, or manuscript content, undeclared write capability increases the risk of users or hosting platforms underestimating where sensitive data may be stored.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The skill generates cover letters for medical and academic use cases, which can contain sensitive personal details, unpublished manuscript information, affiliations, or research claims, yet the documentation does not clearly warn users that this content may be saved to disk. This can lead to accidental local exposure, mishandling in shared workspaces, or retention of sensitive material beyond user expectations.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal