Free Resume Reviewer

Security checks across malware telemetry and agentic risk

Overview

This resume-review skill reads a user-chosen resume PDF to provide feedback, with normal privacy considerations but no evidence of suspicious behavior.

Use this only with resume PDFs you are comfortable having analyzed in the agent context. Consider redacting unnecessary phone numbers, addresses, or other personal details before review. You may need to install pdfplumber in your Python environment for the extraction script to work.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill directs processing of user resume PDFs, which commonly contain sensitive personal data such as full name, email, phone number, location, employment history, and education, without any privacy warning, minimization guidance, or handling restrictions. In context, this increases the risk of unnecessary collection, retention, or propagation of personal data during analysis and feedback generation.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal