Back to skill

Security audit

Placed Career Tools

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Placed API career assistant, but it asks agents to persist and source a plaintext API-key file and can send or modify sensitive career data with limited warnings.

Review before installing. Use this only if you are comfortable sending career-related data to Placed. Prefer setting PLACED_API_KEY only in your current environment or a secure credential manager instead of saving it as a sourced shell file; if you do persist it, restrict file permissions and do not put the token in shared dotfiles or logs. Confirm any delete_job_application call before allowing it to run.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:16
Finding

Executable Credential File Enables Persistent Shell Command Injection

Content
View full analysis
" > "$HOME/.config/placed/credentials" export PLACED_API_KEY= ``` ### Technical Analysis The Skill stores an API key as executable shell syntax and subsequently loads it using `source`. The `source` command does not parse the file as passive credential data; it executes every command in the file with the privileges of the Agent's operating-system user. This design creates two related injection paths: 1. Any local process or actor capable of modifying `~/.config/placed/credentials` can place arbitrary shell commands in it. 2. A user-provided value is interpolated into an unquoted shell assignment. If the supplied value contains shell syntax, such as command substitution, separators, redirections, or line breaks, the generated credential file can become executable attacker-controlled code. For example, a malicious value that results in the following stored content would execute its command whenever the file is sourced: ```bash export PLACED_API_KEY=$(attacker_controlled_command) ``` The creation procedure also relies on the ambient `umask` and does not explicitly set restrictive permissions on either the directory or credential file. Consequently, the plaintext bearer token may be readable by other local users or processes in some environments. Reading a credential is necessary for the declared API functionality, but executing a credential file and storing it without explicit access controls exceed the minimum privileges and behavior required. A non-executable d ...[truncated 1463 chars]
Remediation
View remediation
"$credential_file" chmod 600 "$credential_file" ``` 3. **Never interpolate an untrusted token into shell program text.** Accept the key as data, validate its expected length and character set, and write it using `printf '%s\n' "$value"`. 4. **Prefer an operating-system credential manager** over a plaintext file, such as Secret Service, Keychain, or an equivalent secure token store. 5. **Require explicit user consent before persistence.** Keep the key only in the current process environment unless the user affirmatively requests storage. 6. **Validate existing credential files before reading them.** Reject symbolic links, unexpected owners, and files with group or world permissions. Where supported, verify that the file is a regular file owned by the current user. 7. **Rotate any API key previously stored using the vulnerable procedure** if there is reason to believe the file was accessible or modified by an untrusted party. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
placed_call() {
  local tool=$1
  local args=${2:-'{}'}
  curl -s -X POST https://placed.exidian.tech/api/mcp \
    -H "Authorization: Bearer $PLACED_API_KEY" \
    -H "Content-Type: application/json" \
    -d "{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"tools/call\",\"params\":{\"name\":\"$tool\",\"arguments\":$args}}" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill advertises resume matching, cover letters, salary insights, and company research via a third-party API, which implies transmission of sensitive career data such as resumes, job descriptions, compensation details, and employer targets. Without a user-facing warning or consent step, users may unknowingly send personal or confidential information off-platform.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs users to persist the API key in a plaintext shell file under the home directory and auto-source it later, without any warning about secret handling, file permissions, or safer credential storage. This increases the chance of credential exposure through local compromise, backups, shell inspection, or accidental sharing of dotfiles.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The helper function sends arbitrary tool arguments and an authorization bearer token to an external endpoint, enabling exfiltration of user-provided resume, salary, and job-search data to a remote service. In this skill's context, external transmission is core functionality, but it remains a real security/privacy risk because the content can include highly sensitive personal information.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
placed_call() {
  local tool=$1
  local args=${2:-'{}'}
  curl -s -X POST https://placed.exidian.tech/api/mcp \
    -H "Authorization: Bearer $PLACED_API_KEY" \
    -H "Content-Type: application/json" \
    -d "{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"tools/call\",\"params\":{\"name\":\"$tool\",\"arguments\":$args}}" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents delete_job_application as deleting an application from the tracker, but it does not warn that the action may remove user data or indicate whether deletion is irreversible. For markdown files, destructive behaviors that affect user data should include an explicit warning about data impact or recovery expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The documentation instructs users to send a Bearer token via PLACED_API_KEY, but it does not include any warning to keep the credential secret or avoid exposing it in logs, client-side code, or shared examples. Since markdown guidance covers credential-related behavior, a basic user warning about sensitive token handling is expected.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.