求职&面试智能助手

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only Chinese career coaching skill for resumes, interviews, job tracking, and industry lookup, with no executable code or hidden access.

Safe to install for resume and interview help. Users should still avoid sharing unnecessary personal identifiers, private employer information, or sensitive contact details unless they are needed for the specific career task.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger description is broad enough that ordinary job-seeking conversations could unintentionally activate the skill, causing it to take over interactions outside the user's actual intent. While this is not an exploit in the classic code-execution sense, it can lead to misrouting, unnecessary collection of personal career data, and degraded safety or usability if the assistant enters resume/interview workflows prematurely.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal