Back to skill

Security audit

Talent Scout — Competitor Talent Intelligence

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-coherent for talent scouting, but it silently updates and reinstalls mutable code and handles scraped personal data through external services without enough user control or disclosure.

Review this skill before installing. Only use it in an isolated environment, remove or require explicit consent for the auto-update block, install the toolkit from a verified pinned version, and avoid exposing API keys during installation. Also confirm you are authorized to collect and process LinkedIn profile data and to send it to the configured AI provider.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:64
Finding

Silent Retrieval and Installation of Mutable Remote Code

Content
View full analysis
7 * 86400: os.system(f"cd {repo} && git pull --quiet && pip install -e . -q") stamp.write_text(str(time.time())) EOF ``` ### Technical Analysis The Skill instructs the Agent to silently update a local Git repository every seven days and immediately install the updated source with `pip install -e .`. The update is obtained from the repository's currently configured remote without validating its URL, commit identity, cryptographic signature, package hash, or trusted version. This creates a mutable remote code execution channel. Code reviewed during the Skill audit can be replaced after publication by changes in the upstream repository. A compromised repository, malicious maintainer, modified Git remote, or intercepted dependency chain could introduce arbitrary Python code. Package build hooks, installation metadata, imported modules, or the `talent-scout` executable can then execute that code with the privileges of the Agent process. Use of `os.system` also invokes a shell unnecessarily. Although the current `repo` path is constructed internally and is not directly derived from user input, shell invocation broadens the execution surface and provides no verification that the resolved directory or Git configuration is trustworthy. ### Attack Path 1. An attacker compromises the upstream Git repository, a maintainer account, or the local repository's configured remote. 2. The attacker commits malicious package code, build-system hooks, or a modified `talent-scout` executable. 3. At least seven days elapse since ...[truncated 1118 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:82
Finding

Unpinned and Unverified Third-Party Package Installation

Content
View full analysis
Remediation
View remediation
`. 2. Require package hashes with a hash-locked requirements file and use `pip install --require-hashes`. 3. Publish the authoritative package index, publisher identity, and source repository URL. 4. Include a dependency lockfile covering all transitive dependencies. 5. Replace `pip install -e .` with an explicit, validated absolute path to a trusted checkout, or remove editable installation guidance entirely. 6. Verify that the working directory and repository commit match expected trusted values before installation. 7. Install in an isolated virtual environment or container using a non-privileged account. 8. Review the toolkit source and dependency tree before recommending installation. 9. Keep API credentials unavailable during installation and expose only the credentials required at runtime. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is designed to scrape LinkedIn employee data and send candidate information to AI providers, yet it does not clearly warn about privacy, data handling, or third-party processing. In this context, omission of those disclosures is security-relevant because users may unknowingly collect, transmit, and retain personal data in ways that violate policy, expectations, or legal requirements.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill embeds self-updating behavior that performs git pull and pip install -e . before its primary task, introducing unnecessary code execution and supply-chain risk. Because this runs from a local repo without integrity verification, a compromised repository, branch, dependency, or install script could execute arbitrary code under the user's account.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation claims to 'silently check' for updates, but the code does more than checking: it mutates the repository and reinstalls packages. This mismatch is dangerous because it conceals privileged side effects from the user, reducing transparency and making unexpected code changes more likely to go unnoticed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The silent auto-update executes shell commands and installs packages without any user-facing warning or confirmation. Unattended shell execution tied to package installation materially increases the chance of unauthorized environment changes or arbitrary code execution if the repo or dependencies are tampered with.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.