Back to skill

Security audit

JD - Triage

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent job-description evaluation tool that stores career criteria and evaluation history locally, with no evidence of hidden execution or data exfiltration.

Before installing, understand that this skill keeps local markdown files with career preferences, compensation floors, locations, skills, and job-evaluation summaries. Avoid enabling full raw JD history in a synced or shared workspace unless you are comfortable storing recruiter details or non-public compensation text there.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The README advertises very broad natural-language triggers such as "should I apply to this", "和上次对比", and "what should I learn next", which can easily overlap with ordinary user conversation. In an agent environment, that can cause unintended invocation of this skill on unrelated messages, leading to surprise processing of pasted content, incorrect routing, or accidental writes to the skill's criteria/history files.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill registers on broad natural-language phrases like 'should I apply' and similar equivalents, which can cause unintended activation during ordinary conversation. Because the skill reads and writes persistent local career files, accidental triggering can lead to unsolicited processing or storage of sensitive employment data without a clear user intent boundary.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill persistently stores career criteria and job evaluation history under the user's home workspace, but the description does not warn the user that sensitive employment preferences, compensation floors, skills, and application history will be written locally. This creates a privacy and consent risk because users may provide personal career data expecting transient analysis, not durable storage.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs persistent append-only logging of every job evaluation to a fixed local file, including rejected roles and summaries, without requiring an upfront user opt-in for standard entries. This creates a privacy risk because potentially sensitive career preferences, recruiter messages, company names, and job-search activity are stored by default and retained indefinitely.

Session Persistence

Medium
Category
Rogue Agent
Content
| **Derive from examples** | `/jd-triage learn`, or offered when a profile is thin | Paste a few JDs |
| **Full** | S5 (`update` / `reset`), or user asks | All fields |

Write to `~/.openclaw/workspace/jd_criteria.md` using `assets/criteria-template.yaml`.
Field keys English; values in the user's language.

## Using presets
Confidence
90% confidence
Finding
Write to `~/.openclaw

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.