Back to skill

Security audit

Xihu Hiring

Security checks across malware telemetry and agentic risk

Overview

This is a legitimate hiring-report skill, but it bulk-accesses and locally stores sensitive candidate information without enough confirmation, storage, or cleanup safeguards.

Install only for authorized HR or recruiting operators using the correct Feishu bot permissions. Run it in a private workspace, confirm the output directory before use, treat the Excel and /tmp payload as sensitive applicant data, and delete temporary payload files after report generation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly writes and overwrites an Excel file in the current working directory containing candidate recruitment data, and also stages payload data in /tmp. Although the skill mentions not pasting full PII into chat, it does not provide an upfront warning or require confirmation before persisting sensitive candidate data, which creates privacy and retention risk if run in a shared workspace or on an unsecured machine.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs the agent to fetch approval instances and details from Feishu that include sensitive candidate fields such as name, phone, email, school, employment history, and CV data. Even if this is the intended business function, the skill lacks an upfront privacy notice, authorization check, or user confirmation before bulk-accessing PII, increasing the chance of over-collection or accidental access by an operator who should not run it.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The document instructs storing a payload containing hiring approval data, including names, phone numbers, email addresses, schools, and employment history, in a local file under /tmp without an explicit warning about sensitive personal data handling, retention, access controls, or cleanup. In this skill context, the data is clearly HR/PII, so local persistence increases the risk of unintended disclosure through other local users, logs, crash artifacts, or later reuse of the file.

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.