Back to skill

Security audit

模拟任意角色与经验级别的面试

Security checks across malware telemetry and agentic risk

Overview

This interview simulator is not clearly malicious, but it asks for broad read, write, and command execution abilities that are not well scoped to mock interviews.

Review this skill before installing. It may be acceptable for a controlled test environment, but for normal interview practice it should not need broad command execution or generic file/API automation. Prefer a version that removes exec/write access or clearly explains when those abilities are used and requires explicit confirmation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill is presented as an interview simulator, but later documentation advertises generic file processing, API integration, and command execution. This capability mismatch can mislead users and calling agents into granting broader permissions than necessary, increasing the chance of unintended data access or system actions.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest markets a mock interview simulator, but the described behavior expands into generic automation operations. This is dangerous because agents or users may trust the narrow stated purpose while the skill requests or implies much broader operational authority.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
Command execution is not justified by the stated purpose of simulating interviews, so granting exec creates unnecessary attack surface. In an agent environment, an unjustified exec permission can enable local command abuse, data exposure, environment enumeration, or side effects on the host system.

Vague Triggers

Medium
Confidence
86% confidence
Finding
Overly broad invocation guidance makes it easier for the skill to be activated in ambiguous contexts without clear user intent. When combined with write/exec-capable tooling, vague triggers increase the risk of unintended actions or privilege use during normal conversation flow.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill advertises writing files, using external APIs, and executing commands without clear warnings about privacy, persistence, or system impact. Users may provide sensitive interview or personal data without understanding that it could be written locally, sent externally, or used in side-effecting operations.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.