Jd Translator

Security checks across malware telemetry and agentic risk

Overview

This is a coherent JD analysis and interview-preparation skill with a local parser script, and I found no hidden access, persistence, credential handling, or destructive behavior.

Safe to install for JD and interview-prep use. Be mindful that pasted job descriptions or resumes may contain sensitive personal or company information, and ask explicitly for your preferred output language if you do not want Chinese responses.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation guidance is broad enough that ordinary user phrases like asking to analyze a role could trigger the skill unintentionally. This can cause the agent to enter a specialized workflow without clear user consent, potentially overriding the user's preferred task framing or causing inappropriate data handling for unrelated conversations.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The skill is written entirely in Chinese and its description strongly implies Chinese-language operation, without indicating language negotiation or fallback behavior. If auto-invoked for users communicating in other languages, it may produce responses in an unexpected language, degrading usability and potentially causing misunderstanding in interview preparation advice.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal