Back to skill

Security audit

Campus Candidate Screener

Security checks across malware telemetry and agentic risk

Overview

This non-executable recruiting skill is purpose-aligned, but generated shortlists may expose candidate contact details if shared too broadly.

Install only for authorized recruiting use. Treat candidate resumes, phone numbers, and email addresses as sensitive personal information; consider asking the agent to mask contact details unless full details are needed for outreach, and avoid sharing generated shortlists outside HR or hiring reviewers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill explicitly requires outputting candidates' phone numbers and email addresses in screening results, but it provides no privacy minimization, access control, masking, or handling guidance for personally identifiable information. In an HR screening workflow involving batches of resumes, this increases the risk of unnecessary exposure of candidate PII to broader audiences, logs, transcripts, or downstream systems.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.