Back to skill

Security audit

Anubis Lite

Security checks across malware telemetry and agentic risk

Overview

This skill does what it claims: it analyzes a pasted job description to produce resume guidance, with privacy and Python-install cautions but no evidence of hidden or harmful behavior.

Install only if you are comfortable pasting the full job posting into the agent context and terminal output. Remove recruiter contact details, internal hiring notes, private compensation data, tracking links, or other sensitive text before use, and prefer installing the Python dependency in a virtual environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill reads JOB_DESCRIPTION and then prints the entire contents back to output between markers, with no warning about privacy, retention, or redaction. Job postings can contain recruiter contact details, internal hiring notes, URLs with tracking tokens, or non-public hiring information, so echoing the full text increases the risk of unnecessary disclosure into logs, chat transcripts, or downstream LLM context.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.