Resume & Cover Letter

Security checks across malware telemetry and agentic risk

Overview

This resume-writing skill is coherent and purpose-aligned, but users should treat its inputs and saved outputs as sensitive personal documents.

Before installing, use only resume/profile files you intend the agent to read, avoid unnecessary sensitive details, and review output/career-docs/ before sharing, syncing, or committing it. Do not approve Bash commands unless you specifically requested them, and compile any optional .tex output with shell escape disabled.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly asks for and processes highly sensitive personal data such as name, contact information, location, LinkedIn URL, employment history, and education, but it provides no warning about privacy, retention, or safe handling of that data. Because the skill also has Write/Edit/Bash capabilities and later instructs saving outputs to disk, users may unknowingly expose PII in local files, logs, or shared workspaces.

Missing User Warnings

Low
Confidence
89% confidence
Finding
The skill directs the agent to write multiple files into output/career-docs/ without warning the user that files will be created or potentially overwritten. While the target path is relatively constrained and appears non-malicious, silent file creation can still leak sensitive resume data to disk or overwrite prior documents unexpectedly.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal