Back to skill

Security audit

Dataify Indeed Job Listings

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Dataify integration for creating Indeed job-listing collection tasks, with disclosed token use and user confirmation before API calls.

Install only if you intend to use Dataify to submit Indeed job URLs for collection. Review the confirmation table before approving calls, and only save a Dataify API token locally if you are comfortable storing that credential in your environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:50