Back to skill

Security audit

UseResume

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent resume and cover-letter API skill, but users should understand it sends personal document data to useresume.ai and installs an unpinned npm CLI.

Install only if you are comfortable sending resume, cover-letter, job-description, and related personal data to useresume.ai. Prefer reviewing or pinning the npm CLI version before global installation, and avoid uploading third-party documents unless you have permission.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned Globally Installed Executable Dependency

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README instructs users to create, tailor, and parse resumes and cover letters through an external API, which necessarily involves transmitting highly sensitive personal data such as names, email addresses, employment history, education, and potentially other identifying details. There is no warning about the privacy implications, data handling, retention, or the need to obtain consent before uploading third-party documents, which increases the risk of inadvertent sensitive-data disclosure by agents or users.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 26)May include surrounding context.

Resume

bash
# Create a resume (1 credit)
useresume resume:create --input resume.json

# Create a tailored resume for a specific job (5 credits)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill sends highly sensitive personal data—including resumes, cover letters, contact details, employment history, education, references, and potentially demographic fields—to a third-party API, but the description and usage guidance do not prominently warn users about that external transmission. This can cause unintended disclosure of private or regulated data because an agent may invoke the skill without ensuring the user understands where their documents and extracted contents are being sent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.