Back to skill

Security audit

简历面试题生成器

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent resume-to-interview-question generator with disclosed privacy limits and no hidden execution or data export behavior found.

Before using it, treat resumes as sensitive personal data: prefer anonymized or consented resume text, remove contact details where possible, and use the outputs as interview preparation guidance rather than an automated hiring decision.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manifest declares very broad user-need triggers such as generating interview questions, test questions, and evaluating resume authenticity, which can overlap with many ordinary hiring-related requests. Without tighter activation constraints, the platform may invoke this skill in situations the user did not explicitly intend, causing unintended exposure of resume data to the skill and potentially bypassing more appropriate, narrower tools.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.