Back to skill

Security audit

TalentHR

Security checks across malware telemetry and agentic risk

Overview

This TalentHR skill is not clearly labeled: it presents itself as read/search oriented while its only listed action can change an employee's role.

Review before installing. Only use this skill if you intentionally want an agent to perform TalentHR employee role changes through your connected OOMOL account, and require explicit confirmation of the employee, new role, and business reason before any run.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The manifest and description say the skill is for 'searching and reading data,' but the documented action `change_employee_role` performs a privileged state change. This mismatch can cause an agent or user to invoke the skill under the assumption that it is read-only, increasing the risk of unintended privilege changes in TalentHR.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The safety section states that untagged actions are reads, yet the only listed action, `change_employee_role`, is untagged despite clearly modifying employee roles. That creates a misleading safety signal that could bypass extra caution or confirmation workflows for a sensitive privilege-changing operation.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The instruction to use this skill for 'ANY TalentHR request' is overly broad and encourages routing all TalentHR-related tasks through a skill whose documented scope and safety properties are inconsistent. In context, this increases exposure because even sensitive administrative requests may be handled by a skill presented as a read/search tool.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.