Campus Candidate Screener

Security checks across malware telemetry and agentic risk

Overview

This HR screening skill appears purpose-aligned and non-executable, but it can expose candidate contact details in generated shortlists.

Install only for authorized recruiting workflows. Avoid sharing generated shortlists outside HR or hiring reviewers, and consider asking the agent to mask phone numbers and email addresses unless full contact details are needed for outreach.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly requires outputting candidates' phone numbers and email addresses in the shortlist, which increases unnecessary exposure of personal data. In an HR context this may be operationally useful, but without data-minimization guidance, access controls, or masking rules, the model could disclose sensitive contact details more broadly than needed.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal