Back to skill

Security audit

headhunter-pro

Security checks across malware telemetry and agentic risk

Overview

This recruiting skill is mostly a visible playbook, but it asks for broad candidate profiling, private communication monitoring, and automated outreach that need careful review before use.

Review this skill before installing in a real recruiting workflow. Use it only with explicit candidate and client consent, remove or disable passive monitoring and automated outbound messaging unless legally approved, avoid confidential insider information, minimize stored candidate data, and set clear retention/deletion rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (13)

Ssd 4

High
Confidence
96% confidence
Finding
The sourcing narrative encourages obtaining non-public intelligence from insiders such as former HR staff and using it to preemptively target employees before information is public. That guidance crosses from normal recruiting into covert intelligence gathering and potential misuse of confidential business information.

Ssd 3

High
Confidence
98% confidence
Finding
The CRM Engagement section instructs the system to merge interaction signals across LinkedIn,猎聘, email, WeChat, and phone into unified candidate dossiers with engagement histories. Cross-channel aggregation of behavioral signals substantially increases privacy risk and profiling sensitivity, especially in employment contexts where inferred intent can affect opportunities and treatment.

Ssd 3

High
Confidence
99% confidence
Finding
The asynchronous intake workflow gathers highly sensitive data including current compensation, notice period, non-compete status, dealbreakers, and AI-inferred '真实动机' into reusable briefs. This is dangerous because it combines direct sensitive disclosures with speculative inference, creating a rich dossier that can be reused beyond the candidate's expectations or expose them if leaked.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The Brief Drift Detection section directs the agent to monitor private client communication threads across email/WeChat/Slack to detect informal requirement changes. Monitoring private business communications is a substantial privacy and confidentiality risk, especially because it expands collection beyond the core stated purpose and could capture sensitive, privileged, or unrelated information.

Ssd 3

High
Confidence
98% confidence
Finding
The instructions direct ongoing monitoring and recording of candidate/client communications and requirement changes into reusable records. This creates a centralized store of sensitive personal and commercial data, increasing the consequences of unauthorized access, misuse, or retention beyond the original conversation context.

Credential Access

High
Category
Privilege Escalation
Content
**认证配置:**
```bash
# 方法 1:GitHub Personal Access Token
GitHub Settings → Developer Settings → Personal Access Tokens → 生成 token(建议 scope: repo, read:user)
export GITHUB_TOKEN="your_personal_access_token"
Confidence
70% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Credential Access

High
Category
Privilege Escalation
Content
**认证配置:**
```bash
# 方法 1:GitHub Personal Access Token
GitHub Settings → Developer Settings → Personal Access Tokens → 生成 token(建议 scope: repo, read:user)
export GITHUB_TOKEN="your_personal_access_token"

# 方法 2:GitHub CLI 登录
Confidence
70% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The skill claims '仅文件操作 + 文本生成,无外部网络调用' while extensively instructing network-dependent activities such as LinkedIn/GitHub monitoring, outreach over messaging platforms, API use, and communication-thread monitoring. This mismatch is dangerous because it can mislead users and platform reviewers about the real capability and risk surface, causing unsafe installation or overbroad trust.

Ssd 4

Medium
Confidence
89% confidence
Finding
The management-candidate activation strategy explicitly suggests creating an 'identity recognition crisis' after trust-building to push a candidate toward leaving. This is manipulative and risky because it encourages psychological steering rather than transparent recruiting, increasing the chance of coercive or unethical engagement.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill recommends broad monitoring of candidate and client communications yet does not present prominent, user-facing privacy warnings, consent requirements, or channel-specific boundaries before doing so. In a recruiting context this is especially risky because the data involved often includes sensitive employment, compensation, and business information.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill promotes automated follow-up and outreach over WhatsApp/Telegram/WeChat without clear warnings about consent, anti-spam obligations, rate limits, or reputational risk. That omission can lead users to deploy messaging automation in ways that violate platform policies, privacy expectations, or local communications laws.

Context-Inappropriate Capability

Medium
Confidence
82% confidence
Finding
L5363-L5418 adds a general voice AI workflow for transcribing call recordings and generating spoken audio from reports. While recruitment involves calls, built-in audio transcription/TTS model setup is a distinct capability not mentioned in the manifest description, which focuses on recruiting workflow stages rather than media processing.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The file explicitly sets the skill language to '中文(Chinese)' while also presenting an English display description and cross-platform usage, but it does not state that language is optional or region-specific. Under the policy, forcing a specific language without opt-in can be a locale-policy violation unless the constraint is justified and clearly documented.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.