Back to skill

Security audit

简历助手免费版

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward resume scoring, polishing, and export helper, with ordinary privacy considerations for resume data but no evidence of hidden or malicious behavior.

Before installing, remember that resumes often contain personal information. Use this skill only with resume content you are comfortable giving to your agent or LLM provider, avoid unnecessary sensitive details, use callback URLs only when trusted, and store exported Markdown or HTML files in locations you control.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
This skill processes resumes, which commonly contain sensitive personal data such as names, phone numbers, email addresses, employment history, and sometimes addresses. Omitting a privacy warning increases the chance that users will submit unnecessary sensitive data or that agents will handle it without clear minimization, retention, or redaction guidance.

Missing User Warnings

Low
Confidence
88% confidence
Finding
The export feature creates Markdown or HTML artifacts, but the documentation does not warn users that generated files may persist on disk or be shared further. For resume content, this can expose personal information through local files, browser history, sync folders, or accidental distribution.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.