Back to skill

Security audit

Job Search

Security checks across malware telemetry and agentic risk

Overview

This skill is a normal job-search helper that uses a local MCP server to query named external job boards, with no hidden destructive behavior found.

Install only if you are comfortable running the referenced JobSpy MCP server and sending job-search terms, locations, and filters to external job sites. Use a virtual environment, review the third-party server and packages, keep result counts reasonable, and avoid including sensitive personal details in search queries.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs agents to send user-supplied job search terms, locations, and related filters to multiple third-party job boards, but it does not disclose that this data leaves the local agent environment. This can expose potentially sensitive employment interests, location data, and search behavior to external services without informed user consent, especially when queries may contain personal or strategic career information.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.