Back to skill

Security audit

Job Auto Apply Tool Free

Security checks across malware telemetry and agentic risk

Overview

The skill is a job-application automator with expected personal-data and platform-access needs, but its broad trigger, optional confirmation, and weak privacy/credential guidance warrant Review before use.

Install only if you are comfortable giving an agent access to your resume/profile data and job-platform credentials. Use dry-run first, require manual confirmation for every submission, keep tokens out of prompts and tracked files, and review what data will be sent to LinkedIn, Indeed, any scraping/API path, and any LLM used for cover-letter generation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger conditions are broad enough to activate this skill for generic automation or workflow requests outside narrowly scoped job-application tasks. In an agent environment with exec/read/grep/glob access, overbroad invocation increases the chance the agent handles sensitive profile data or performs unintended actions when the user did not explicitly request job-platform submissions.

Missing User Warnings

High
Confidence
94% confidence
Finding
The skill processes highly sensitive personal data including name, email, phone, resume, work authorization, and external profile URLs, and sends it to third-party job platforms and possibly LLM-backed cover-letter generation. Without a clear privacy warning and data-handling disclosure, users may unknowingly expose personal, employment, and identity data to external services, increasing the risk of over-sharing, unauthorized retention, or secondary use.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The documentation instructs users to export API keys and access tokens but does not warn about secure storage, log exposure, shell history leakage, or accidental inclusion in prompts and files. In an agent-assisted environment, credentials can easily be echoed, persisted, or mishandled, enabling unauthorized access to job-platform accounts and associated personal data.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.