Back to skill

Security audit

Skill Salary Market Analysis

Security checks across malware telemetry and agentic risk

Overview

The skill mainly processes salary data locally, but its guidance includes bulk web scraping and proxy use that should be reviewed before installation.

Install only if you will keep data collection to authorized sources, avoid proxy or anti-blocking tactics, store outputs in a dedicated folder, exclude personal or confidential data, and manually verify sources before using reports for compensation decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Lp3

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding
The skill advertises executable processing steps and file transformations that imply read/write access, but it does not explicitly declare permissions or clearly bound filesystem scope. This creates an authorization and transparency gap: an agent or user may run code that reads input files and writes reports without clear consent boundaries, increasing the risk of unintended file access or overwrite.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The guide explicitly recommends using proxies to avoid IP-based blocking during automated scraping. That crosses from ordinary data collection into evasion of access controls or rate-limiting, which increases the likelihood of abusive collection and policy violations even if the overall skill is framed as salary research.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The template explicitly asserts that the report is based on real market data from genuine sources, but the file itself is only a placeholder template with no validation, provenance checks, or enforcement mechanism. This can mislead downstream users into treating generated output as verified factual analysis, creating integrity and compliance risks in compensation decisions.

Missing User Warnings

Medium
Confidence
81% confidence
Finding
The skill encourages multi-source collection and processing of compensation data but does not warn about personal data, confidential employer information, or regional privacy obligations that may be present in postings or manually collected records. In practice, analysts could aggregate names, company details, links, and free-text notes containing personal or sensitive information without minimization, retention, or compliance controls.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The Tampermonkey workflow promotes automated extraction and CSV export from recruitment sites without any explicit authorization, privacy, or data-handling safeguards. Even if the target data is job-posting information, the pattern normalizes scraping behavior that can collect more than intended and store data locally without controls.

Missing User Warnings

Medium
Confidence
82% confidence
Finding
The Chrome extension section describes background-style automatic collection during browsing and periodic export, but gives no notice about what is captured, when collection occurs, or how stored data is protected. This creates risk of overcollection and covert local data accumulation beyond the narrow salary-analysis purpose.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The Playwright section provides end-to-end high-volume scraping instructions, selectors, output handling, and anti-blocking operational advice with only minimal mention of robots.txt. In context, this materially enables large-scale collection and operational misuse, especially because it includes practical implementation details rather than a high-level discussion.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.