Back to skill

Security audit

hiring-memory

Security checks across malware telemetry and agentic risk

Overview

This skill is purpose-built for hiring memory, but it pushes candidate and interview details into an external persistent memory service without clear consent, retention, or minimization controls.

Review this skill before installing in a recruiting workflow. It may be useful if your organization has approved BlueColumn for hiring data, but users should avoid storing unnecessary personal details, protected-class information, interview notes subject to policy restrictions, or data that must not leave approved systems. Require explicit user approval and a retention/deletion process before saving candidate records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly encourages sending candidate and interview information to an external persistent memory service, but it does not warn users that personal hiring data will leave the local agent context and be stored remotely. Because hiring data commonly contains sensitive personal and employment-related information, this omission can lead to unauthorized disclosure, privacy violations, and noncompliant processing without meaningful user awareness or consent.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
The examples and workflow normalize storing identifiable candidate information and interview status by default, with no mention of user choice, minimization, retention limits, or jurisdiction-specific privacy constraints. In a recruiting context, this is risky because hiring records may contain personal data whose collection, storage, and cross-system transfer are regulated or require explicit organizational approval.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.