Back to skill

Security audit

计算机行业转行规划助手

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent career-planning assistant that asks work-history questions and generates a local HTML report, with no evidence of hidden execution, credential use, exfiltration, or destructive behavior.

Install only if you are comfortable answering detailed career-planning questions and storing the resulting HTML report in your workspace. Review or delete the report if it contains sensitive personal details, and note that opening it may load Chart.js from a third-party CDN.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list contains broad phrases such as general career-planning and job-transition terms that can match ordinary conversation outside a narrowly scoped invocation context. This can cause unintended activation, leading the agent to collect extensive personal/career information and steer the conversation into a long workflow when the user may not have intended to invoke this skill.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation scenarios are documented very broadly, including emotional states and vague exploration of alternatives, without clear boundaries for when the skill should not run. In context, this increases the chance of over-triggering a workflow that asks 30 questions and produces a file, creating privacy and consent concerns from accidental invocation.

Missing User Warnings

Low
Confidence
82% confidence
Finding
The skill writes an HTML report file to the workspace but does not clearly disclose this behavior in the user-facing description up front. Even though the file creation is part of the intended functionality, lack of notice reduces informed consent and may surprise users with persisted artifacts containing sensitive career and personal assessment data.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.