OfferClaw留学申请简历助手

Security checks across malware telemetry and agentic risk

Overview

This CV-writing skill is mostly coherent, but its PDF export can add an OfferClaw footer by default and installs third-party Python packages on first export.

Install only if you are comfortable with a CV helper that handles personal education/contact details locally and may install Python packages for PDF export. Before submitting any exported PDF, check for the OfferClaw footer and use the documented watermark-off option if you do not want branding on the file.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill invokes file reads and shell execution without declaring corresponding permissions, which weakens the platform's ability to warn, sandbox, or obtain informed consent. In this skill's context, those capabilities are used for reference loading and PDF export, so the risk is operational overreach rather than obviously malicious behavior, but undeclared code-capable actions can still enable unintended file access or command execution.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The skill description frames the capability as CV writing and PDF export, but the instructions also authorize creating a virtual environment, installing dependencies from the internet, and the finding indicates a default watermark/footer behavior not disclosed in the user-facing description. This mismatch is dangerous because users and security controls may approve a benign writing tool while it performs software installation and modifies deliverables in ways that exceed reasonable expectations.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
Automatic internet-based dependency installation introduces supply-chain and execution risk that is not necessary for core CV drafting. Even if performed in an isolated venv, downloading and executing packages at runtime expands the attack surface and can be exploited through compromised dependencies, typosquatting, or unexpected install scripts.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The guide mandates that each bullet be produced in English first regardless of the user's preferred language or explicit opt-in. This can cause the skill to disregard user language expectations, create privacy or accessibility issues for users who cannot adequately review English content, and reduce user control over generated application materials.

VirusTotal

67/67 vendors flagged this skill as clean.

View on VirusTotal