Back to skill

Security audit

Career Coach Ai

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent career-coaching assistant, but it tells the agent to persist potentially sensitive career details without explicit user notice, consent, retention limits, or deletion guidance.

Install only if you are comfortable with the agent potentially saving your career-coaching intake details across sessions. Avoid sharing employer names, coworker names, compensation specifics, or sensitive workplace conflicts unless you explicitly want them retained, and ask the agent not to write to USER.md or to delete stored notes if persistence is enabled.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to write user-provided details into USER.md if persistence is available, but it does not require clear user notice or consent before storing conversation data. In a career-coaching context, the captured details may include employment history, job-search status, workplace conflicts, compensation discussions, and emotional state, which are sensitive and can be retained longer than the user expects.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The file instructs the agent to write a user's career details into persistent storage (USER.md) without any notice, consent, retention limit, or data-minimization guidance. Career history, role, industry, current problems, and time pressure are personal profile data; silently persisting them increases privacy risk and can expose sensitive employment information across sessions or to other components.

Ssd 3

Medium
Confidence
97% confidence
Finding
Persisting conversation details to USER.md creates a data retention and unintended disclosure risk because the file may later be read by the agent or other components outside the user's immediate expectation. In this skill, even the initial triage questions collect potentially sensitive professional and emotional information, so natural-language notes can become a durable record that increases privacy exposure.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.