Back to skill

Security audit

Job Screener Engine

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed job-evaluation helper that collects user preferences and searches company information, with privacy caveats users should understand before use.

Before installing, be aware that the skill may ask for sensitive job-search preferences and save them in references/user_profile.md, and it uses WebSearch to research companies or roles. Use it when you are comfortable storing that profile locally and sharing target company or role names with the search tool; review or delete the profile file when it is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The documented trigger phrase is broad enough that normal user conversation about job opportunities could unintentionally activate the skill. In an agent ecosystem, ambiguous invocation can cause the model to gather data, ask setup questions, or perform evaluation steps the user did not explicitly intend, which is a real prompt-routing and consent issue.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The usage section reinforces vague trigger phrases without defining boundaries, making accidental activation more likely across common chat contexts. Because this skill may initiate profile collection and job-analysis workflows, ambiguous triggering can lead to unnecessary collection of personal preferences or unintended external searches.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger phrases include very generic expressions such as '评估一下' and '值得投吗', which can overlap with ordinary conversation and cause unintended skill activation. In a skill that asks for user profile data and may invoke WebSearch, accidental activation can lead to unnecessary collection of sensitive preferences and external transmission of job-target details.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly solicits salary floor, expected compensation, target city, work-style preferences, and career direction, but provides no privacy notice, retention guidance, or minimization language. This creates a real privacy risk because highly sensitive employment preferences could be exposed, over-collected, or reused beyond the user's expectations.

Missing User Warnings

Low
Confidence
92% confidence
Finding
The workflow requires WebSearch on company and role-related information without clearly warning the user that their provided job target details may be sent to an external search tool. Even if the searched entities are often public companies, a user's private interest in a specific employer or role can still be sensitive and reveal job-seeking activity.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill directs the agent to automatically generate and write `references/user_profile.md` after collecting salary expectations, work status, city preferences, and other personal preference data, but it does not require explicit user consent for persistence or warn that the data will be stored on disk. This creates a real privacy and data-handling risk because users may believe they are only answering conversational questions, not authorizing durable storage of sensitive profile information.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.