Back to skill

Security audit

Talent Radar

Security checks across malware telemetry and agentic risk

Overview

This skill is a legitimate resume/job matching tool, but it needs Review because its hiring-screening guidance contains inconsistent fairness instructions and broad PDF extraction guidance.

Review this carefully before installing in any real hiring workflow. Use it only as human-reviewed assistance, avoid relying on school prestige, age, gender, or other protected/proxy attributes, and prefer the bundled matcher behavior over the older reference docs. Only run PDF extraction commands on files you intentionally provided and after checking the command and file path.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The skill’s fairness section says school name will not be used for scoring, but the capability description later lists '院校' under education matching. In a hiring context, this inconsistency can reintroduce proxy discrimination or mislead deployers into believing the system is fairer than it is, creating compliance and bias risk even if the behavior is accidental.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The README claims the tool does not evaluate candidates based on school name, gender, or age, but later states the education matching dimension includes '院校' as a scoring factor. In a hiring context, this contradiction can enable discriminatory screening or mislead users about fairness guarantees, creating legal/compliance risk and unfair outcomes even if the issue is only in documentation or design intent.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The guide explicitly advises using the terminal to invoke a system Python interpreter outside the normal skill/runtime boundary. In an agent context, this broadens the operational scope from document analysis to local command execution patterns, which can encourage unsafe handling of untrusted file paths and create a pathway for filesystem access or arbitrary command use beyond the intended skill purpose.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.