Back to skill

Security audit

resume-evaluation-report

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only resume review skill that handles sensitive hiring context but does not show hidden code, persistence, credential use, or data exfiltration.

Install only if you intend to use it for recruiting or resume review. Provide resumes intentionally, avoid using it for general personal profiling, and have a human verify facts, fairness, and legal compliance before acting on any pass/fail recommendation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill metadata includes broad trigger phrases such as '帮我看看这个候选人' and '评估一下这个人', which can match ordinary conversation without clearly requiring a resume-analysis task. This can cause unintended activation on unrelated people-analysis requests, leading the agent to process sensitive personal data or produce hiring-style judgments outside the user's actual intent.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation rule '用户发送简历文件并要求评估,或明确要求对候选人进行分析' lacks strict boundaries and does not define exclusions, so the skill may activate for vague 'analyze this person' requests even when no hiring context is present. Because this skill generates structured strengths, risks, and interview probes, accidental invocation can amplify privacy and profiling risks against real individuals.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.