Back to skill

Security audit

job-match-priority

Security checks across malware telemetry and agentic risk

Overview

This skill appears to perform disclosed resume-to-job matching, but users should know it can process sensitive resume data and update Feishu tables or create result files.

Install only if you are comfortable sharing resume content and job data with the agent workflow. Redact unnecessary personal details when possible, verify which Feishu table or local file will be read or updated, and ask for a dry run or confirmation before writing results back to shared tables.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Confidence
81% confidence
Finding
The auto-trigger condition is broad enough that an agent could invoke this skill on common recruiting or resume-related requests without strong user intent confirmation. In agentic systems, overbroad routing can cause unnecessary access to resumes, job descriptions, preferences, or external data sources, increasing the chance of unintended data handling or action selection.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The trigger condition is broad enough to activate on common recruiting-related requests without clear boundaries, increasing the chance the skill processes resumes, job listings, or preference data unexpectedly. In a skill that reads local files and writes results to external tables or new files, over-broad triggering can lead to unintended handling of sensitive employment and personal data.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The workflow asks for resume files or pasted resume text, which commonly contain highly sensitive personal data, but it does not prominently warn about privacy risks, minimization, retention, or handling constraints. This creates a real risk of exposing PII or processing more candidate data than necessary, especially if the agent later persists or transmits derived outputs.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill describes reading and writing Feishu tables and creating local result files without clear advance notice of external data handling and data modification. Because candidate/job datasets may include personal and confidential business information, silent or poorly disclosed writes can cause unauthorized disclosure, persistence, or accidental alteration of records.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The guide instructs users to provide resumes and local file paths, which can expose sensitive personal data and system information, but it gives no warning about privacy, retention, redaction, or safe handling. In a job-matching skill, this context makes the issue more credible and risky because resumes commonly contain phone numbers, email addresses, employment history, and other personal data, and local paths may leak device or organizational details.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The skill content is entirely in Chinese and directs user interaction in Chinese without offering a language choice or fallback. This can cause users to misunderstand filtering criteria, thresholds, or ranking outputs, leading to incorrect job prioritization and reduced accessibility for non-Chinese-speaking users.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.