Back to skill

Security audit

Anubis

Security checks across malware telemetry and agentic risk

Overview

This resume helper appears purpose-aligned, but it needs review because it prints full resume and job-description contents into plain console output.

Install only if you are comfortable with your full resume and job description being visible in the agent transcript, terminal output, and any logs for the session. Avoid shared or hosted environments for sensitive applications, choose OUTPUT_DIR deliberately, and check for existing same-date files before saving.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
98% confidence
Finding
The skill prints the full resume and full job description to stdout, which exposes sensitive personal and application data beyond what is needed to perform the rewrite. In agent/runtime environments, stdout is often logged, surfaced to users, or retained in telemetry, creating unnecessary disclosure risk.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill description omits important side effects: it reads resume contents, processes potentially sensitive personal data, and writes submission-ready files. This can undermine informed consent and safe use, especially in agent systems where users rely on metadata to understand what a skill will access and modify.

Ssd 3

Medium
Confidence
98% confidence
Finding
Dumping the complete resume and job description into plain output unnecessarily reveals personal, professional, and possibly confidential employer information. Because this skill handles highly sensitive application materials, plaintext output materially increases the chance of leakage through logs, transcripts, or shared consoles.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.