Cybersecurity Career

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward cybersecurity career-assessment API, but users should avoid sending unnecessary personal or employer information.

Install only if you are comfortable sending career-profile information to the external assessment service. Use pseudonymous identifiers where possible, omit unnecessary name, email, company, candidate, or employee data, and confirm the provider's privacy practices before submitting sensitive employment information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill documentation explicitly describes collecting personal and professional profile data, including name, email, company, career history, and goals, but provides no privacy notice, retention policy, consent language, or data-handling constraints. In a career-assessment context this is sensitive personal information that could be transmitted to a third-party API without users understanding how it is stored, shared, or protected.

Vague Triggers

Low
Confidence
88% confidence
Finding
The /api/career/assess operation is described only as 'Career Assessment' and 'Perform cybersecurity career assessment', which does not meaningfully constrain when the skill should be selected or what inputs are appropriate. In an agentic environment, vague operation descriptions can cause overbroad invocation, accidental routing of unrelated user data, and misuse of the endpoint beyond its intended scope.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal