AI ML Engineer

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward career-roadmap API; it sends relevant career profile details to an external service but shows no hidden code execution, credential use, or destructive behavior.

Install only if you are comfortable sharing career-assessment details with this external roadmap service. Avoid submitting sensitive employer-confidential information or unnecessary identifying details, and use an anonymous or null userId where possible.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill requests and documents collection of detailed career-assessment data together with persistent identifiers such as sessionId, userId, and timestamps, but provides no privacy notice, retention guidance, minimization rationale, or handling constraints. This increases the risk of unnecessary collection, correlation, and exposure of user profiling data, especially because the service is external and the identifiers enable tracking across requests.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal