Back to skill

Security audit

career-coach-ai

Security checks across malware telemetry and agentic risk

Overview

This career-coaching skill is mostly coherent, but it tells the agent to persist potentially sensitive work and emotional-context details without clear user consent or deletion controls.

Review before installing. The skill appears to be a normal career-coaching prompt with no executable code, but it may cause your agent to remember personal workplace details. Avoid sharing real names, company names, health details, identifiers, or anything you would not want saved, and use it only where you are comfortable with session memory.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description is broad enough to match many ordinary career or workplace conversations, which can cause over-invocation and unnecessary routing of general user queries into this skill. While not directly malicious, broad activation increases the chance the skill handles contexts it was not intended for, including sensitive employment, mental-health-adjacent, or personal data discussions.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The scenario triggers use vague phrases like anxiety, confusion, conflict, or wanting promotion, which overlap heavily with common conversation and do not impose clear invocation constraints. This ambiguity can lead to the skill being selected inappropriately, creating prompt-scope confusion and increasing the risk of collecting sensitive workplace or emotional details outside a tightly defined need.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to write sensitive career and emotional-state information into USER.md whenever persistence is available, but it does not require explicit user notice or consent before storing that data. Because the collected fields include employment details, stressors, and anxiety-related information, this creates a privacy risk from unnecessary retention, later reuse across sessions, or exposure to other tools/operators.

Ssd 3

Medium
Confidence
98% confidence
Finding
The instruction to write key user information into USER.md introduces a retention and privacy risk because it encourages persistent storage of user-supplied personal and employment details in natural language. In this skill's context, those details may include job history, workplace conflicts, timelines, and emotionally sensitive information, which increases exposure if stored unnecessarily or without minimization and consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.