Back to skill

Security audit

maker-hunter

Security checks across malware telemetry and agentic risk

Overview

This skill is a recruiting automation tool, but it asks users to hand over raw platform cookies and stores collected candidate data without clear safeguards.

Review before installing. Use only with accounts you are willing to automate, do not provide raw cookies or session tokens, prefer interactive login or scoped APIs, review every outreach message manually, and periodically delete any stored credentials and candidate memory.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Context-Inappropriate Capability

High
Confidence
94% confidence
Finding
The skill references a credentials file for platform access even though the core task is candidate discovery and outreach generation. Introducing credential handling expands the trust boundary and creates unnecessary exposure of authentication material that could be leaked, reused, or mishandled.

Context-Inappropriate Capability

Critical
Confidence
99% confidence
Finding
The skill explicitly instructs the user to open developer tools, extract cookie values, and provide them to the agent. Raw session cookies are equivalent to account access in many platforms, so this creates direct credential exfiltration capability far beyond the stated recruiting purpose.

Missing User Warnings

High
Confidence
92% confidence
Finding
The skill directs collection and display of detailed candidate profile data, links, and personalized DM content without any privacy notice, minimization, or consent guardrails. This can expose personal data in chat logs and facilitate mass profiling or outreach misuse.

Missing User Warnings

High
Confidence
99% confidence
Finding
Requesting cookie extraction without warning about credential sensitivity is a severe security issue because users may unknowingly hand over active session tokens. In this context, the lack of warning worsens an already dangerous instruction to exfiltrate secrets.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The guide provides broad outreach templates, platform-specific customization, and targeting keywords for identifying and contacting people across multiple communities, but it lacks clear boundaries on authorized use, consent, rate limits, anti-spam safeguards, or prohibited contexts. In a recruiting automation skill, that omission makes it easier to repurpose the content for mass unsolicited profiling and messaging, increasing abuse risk even if the underlying content is framed as legitimate outreach.

Missing User Warnings

High
Confidence
97% confidence
Finding
The document directly instructs users to retrieve and copy authenticated platform cookies from browser developer tools, which are sensitive session credentials. Exposing or reusing those cookies can enable account takeover or unauthorized access if mishandled, and in this skill context they appear intended to facilitate platform access or automation without any security warnings or safer alternative authentication flow.

Ssd 3

Medium
Confidence
89% confidence
Finding
The skill requires outputting full candidate details and generated outreach messages directly in the conversation, which increases the chance of unnecessary personal data exposure through logs, screenshots, or downstream retention. This is especially risky because it aggregates multiple profiles into one easily copied transcript.

Ssd 3

Medium
Confidence
88% confidence
Finding
Persistently storing discovered individuals and daily results in local memory files creates retention risk, especially when the data contains profiles, links, and outreach context. Over time this builds a searchable dossier that could be exposed to other tools, users, or future runs.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.