Back to skill

Security audit

General Talent Grader

Security checks across malware telemetry and agentic risk

Overview

This hiring-assessment skill is mostly coherent, but it can automatically process sensitive candidate materials and produce employment-impacting grades without enough privacy scoping or user confirmation.

Review before installing in hiring workflows. Only use it with candidate materials you are allowed to process, redact unnecessary personal data, and treat its L1-L4 grading as decision support rather than an automated hiring decision. Ask the agent to confirm before analyzing uploaded resumes or interview notes, and be aware that some legacy ai-talent-grader references may affect scoring consistency.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The checklist says it must run 'ai-talent-grader' while the manifested skill is 'general-talent-grader'. In an agent system, mismatched skill identity can cause the wrong pre-flight procedure, validation logic, or policy assumptions to be applied, leading to skipped checks or execution under an unintended workflow. In this hiring-assessment context, that increases the chance of unreliable or policy-inconsistent candidate evaluations rather than direct system compromise.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The README instructs users to supply resumes and interview records but does not warn that these inputs contain highly sensitive personal data and will be processed by the skill. This can lead users to upload PII, employment history, contact details, compensation information, and potentially special-category data without informed consent or appropriate handling expectations, increasing privacy and compliance risk.

Vague Triggers

Medium
Confidence
84% confidence
Finding
Overly broad trigger conditions can cause the skill to activate during ordinary recruiting conversations that did not request formal candidate grading. In an HR context, unintended activation is dangerous because it may process sensitive personal data, generate evaluative judgments without clear user intent, and increase privacy and fairness risk.

Vague Triggers

Medium
Confidence
87% confidence
Finding
Automatic activation on uploaded resumes or interview records is especially risky because those files contain highly sensitive personal and employment information. If the skill runs merely because a document was uploaded, it may analyze PII and infer candidate fitness without explicit consent or a clear task boundary.

Natural-Language Policy Violations

Medium
Confidence
81% confidence
Finding
The file is entirely written as mandatory Chinese-language operating instructions without any user opt-in or locale justification. This can cause the agent to respond in a language the user did not request, degrading transparency, correctness, and auditability; for a hiring-grader skill, that may also affect fairness if users or reviewers misunderstand scoring rationale or interview follow-ups. The issue is contextual rather than exploit-driven, but it can still produce unsafe or unusable outputs.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.