Back to skill

Security audit

headhunter-pro

Security checks across malware telemetry and agentic risk

Overview

The skill is a recruiting assistant, but it under-discloses external sourcing and monitoring workflows and encourages sensitive candidate profiling that users should review before installing.

Install only after deciding whether you want the external sourcing, monitoring, token-based GitHub, and candidate-record workflows. Remove demographic fields from default reports, obtain written authorization for background checks, obtain consent before recording or transcribing calls, and define retention/deletion rules for candidate records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The skill explicitly claims '仅文件操作 + 文本生成,无外部网络调用', yet large sections instruct use of GitHub CLI, LinkedIn, third-party recruiting platforms, online demos, and scheduled monitoring of external services. This creates a misleading trust boundary: users may approve or install the skill believing it is offline/local-only when its documented workflow depends on networked access and external data exchange.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The top-level description presents a recruitment workflow toolkit, but the body expands into broader operational behavior such as OS scheduling, passive monitoring, GitHub/LinkedIn scanning, automated follow-up, and third-party tooling. This is a scope-transparency issue because users may not realize the skill implies surveillance-like monitoring and external service operations beyond ordinary document generation.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The README explicitly grants write access to candidate profile and recommendation files but does not describe safeguards for preserving integrity, auditability, or preventing unintended overwrites of stored candidate data. In a recruiting workflow, these files may contain sensitive personal and evaluative information, so silent modification can lead to privacy issues, corrupted records, or unfair hiring decisions.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The quick-start instructions invite users to paste resumes, JDs, and candidate materials without an upfront privacy, consent, retention, or lawful-use warning. Because resumes contain sensitive personal and employment information, encouraging immediate ingestion without first framing compliance obligations increases the risk of unlawful collection, over-processing, or accidental disclosure.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill includes a background-check workflow and multidimensional verification handling highly sensitive employment and reputation data, but the invocation guidance does not prominently require prior authorization and lawful processing. Background checks can expose the operator to serious privacy, labor-law, and defamation risk if conducted without explicit consent, purpose limitation, and documented controls.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill recommends recording and transcribing candidate calls and meetings, but does not clearly require obtaining consent before recording or explain applicable two-party/all-party consent laws. Unauthorized recording and transcription can create significant legal exposure and capture sensitive personal, employment, and negotiation information at scale.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The file hardcodes Chinese as the output language for the skill's expected response structure without indicating that the language is derived from user preference or a documented business requirement. This can cause unsafe or exclusionary behavior in multilingual contexts, lead to user misunderstanding, and make the skill less reliable when used by operators or candidates who expect another language.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The template explicitly instructs inclusion of sensitive personal data such as birth date, gender, marital status, location, compensation details, and inferred motivations, but provides no privacy notice, consent requirement, minimization rule, or jurisdictional compliance guardrails. In a recruiting workflow, this is especially dangerous because the data is highly identifiable, often regulated, and can be propagated into reports and outreach materials, creating privacy, discrimination, and downstream misuse risk.

Natural-Language Policy Violations

High
Confidence
98% confidence
Finding
The template mandates demographic attributes in candidate reporting, including gender, marital status, and age-adjacent birth information, which can directly enable biased hiring decisions or unlawful discrimination. In the hiring context, this makes the issue more dangerous because these attributes are generally irrelevant to merit-based evaluation and are protected or sensitive in many jurisdictions and policies.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The rubric explicitly awards top scores for candidates from '985/211' universities, embedding a protected or proxy-based educational prestige preference into a hiring workflow. In a recruitment skill, this is especially dangerous because it can systematically bias screening decisions, create discriminatory outcomes, and expose users to compliance, fairness, and reputational risk across jurisdictions.

Ssd 3

Medium
Confidence
95% confidence
Finding
The instructions direct long-term logging and retention of detailed candidate data across interactions, including motivations, communication records, inferred states, and follow-up metadata. Persistent accumulation of sensitive HR data without clear minimization, retention limits, access controls, or deletion policy increases the blast radius of any misuse or breach.

Ssd 3

Medium
Confidence
94% confidence
Finding
The candidate profile templates encourage storing extensive personal details, motivations, contact history, inferred job-seeking status, and timing signals over time. In HR contexts, these are sensitive employment-related profiles, and retaining them broadly without explicit governance can enable discriminatory inference, privacy violations, and harmful secondary use.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.