Back to skill

Security audit

jd-market-research

Security checks across malware telemetry and agentic risk

Overview

This skill is a plausible recruiting research helper, but it saves and reuses sensitive company hiring and compensation details without clear retention, deletion, or no-save controls.

Install only if you are comfortable with the agent keeping employer recruiting details in a local Markdown profile. Avoid entering confidential compensation strategy, target-company lists, hiring constraints, or internal notes unless you have permission, and review or remove `references/company-profile.md` before using the skill for another company.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The skill goes beyond passive JD market research and directs the agent to manage recruiting operations by checking for saved company records, confirming HR-supplied internal details, and generating hiring playbooks. This scope expansion increases the chance that sensitive internal recruiting data will be collected, retained, and reused without clear disclosure, consent boundaries, or minimization controls.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The documentation explicitly instructs writing company information into `references/company-profile.md`, despite the skill presenting itself as an analysis workflow. Persisting compensation bands, hiring urgency, target companies, and internal preferences to local files creates a confidentiality and privacy risk, especially if users do not expect storage or if other skills/processes can later access those files.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
This section defines an ongoing persistent company profile containing sensitive recruiting and compensation intelligence, including salary structure, equity details, target leveling, hiring preferences, and internal notes, and instructs repeated updates over time. Maintaining such a dossier materially increases exposure of proprietary HR data and could enable internal surveillance, competitive intelligence leakage, or misuse by later prompts or tools that read local references.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs saving potentially sensitive recruiting data to a local markdown file without any user-facing warning that the information will persist beyond the current interaction. Because the stored fields can include salary budgets, hiring plans, and strategic preferences, silent persistence creates a significant confidentiality and expectation-of-privacy risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.