It Support Engineer

Security checks across malware telemetry and agentic risk

Overview

This appears to be a straightforward career-roadmap API skill, with a privacy caution because it sends career profile details and identifiers to an external provider.

Install only if you are comfortable sending your role, experience, skills, certifications, goals, sessionId, timestamp, and optional userId to the provider. Avoid including employer-confidential details, personal contact information, or security-sensitive infrastructure information unless you have independently verified the provider and its privacy practices.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The sample request includes persistent identifiers such as sessionId and userId along with detailed career assessment data, but the skill provides no privacy notice, data minimization guidance, retention policy, or warning that this information is sent to a third-party API. In an agent skill context, this can lead to unnecessary disclosure of personal or profile data to an external service without informed consent or clear handling expectations.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal