Back to skill

Security audit

Anubis Pro

Security checks across malware telemetry and agentic risk

Overview

This resume-writing skill broadly does what it advertises, but it exposes sensitive resume and job-description text in console output without clear warning.

Review before installing. Use only in a private session, avoid confidential job descriptions unless you are comfortable with them appearing in terminal or agent logs, and consider removing the two print statements before use. Prefer running the install in a virtual environment rather than using --break-system-packages.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Medium
Confidence
99% confidence
Finding
The skill prints the full resume and full job description to stdout, which can expose highly sensitive personal data, employment history, contact details, and potentially confidential job-posting content to logs, terminals, or upstream systems that capture command output. This disclosure is not necessary for the stated functionality and increases the data exposure surface well beyond generating application documents.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.