Back to skill

Security audit

AI时代职业规划助手

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent career-planning purpose, but its generated HTML report can execute unsafe user-derived content and loads a remote chart script without integrity protection.

Review before installing. Use it only if you are comfortable sharing career details, and avoid entering salary or location unless needed. Generated reports should be treated as sensitive local files; prefer a version that escapes user input, avoids generated JavaScript, bundles or integrity-pins Chart.js, and asks before creating the HTML report.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
assets/report_template.html:234
Finding

Unescaped Dynamic Content Can Enable Script Injection in Generated Reports

Content
View full analysis
AI时代职业规划报告 - {{USER_NAME}} ``` ```html
{{CURRENT_ROLE}} {{INDUSTRY}} {{YEARS_EXP}}年经验 {{REPORT_DATE}}
``` ```html {{TASK_ANALYSIS}} ``` ```html
{{TIER1_RECOMMENDATIONS}}
``` ```html
{{WEEKLY_ACTION}}
``` ```html ``` The corresponding generation instruction in `SKILL.md:252-273` states: ```text 2. Replace all `{{PLACEHOLDERS}}` with computed data: ``` It then maps user-derived and generated values directly to placeholders, including: ```text | `{{CURRENT_ROLE}}` | Q1 | Current job title | | `{{TASK_ANALYSIS}}` | Generated HTML | Task-level risk table | | `{{COMPETENCY_RADAR_DATA}}` | Phase 3 scores | JavaScript radar chart data | | `{{SCORE_CHART_JS}}` | Generated JS | Gauge chart initialization | ``` ### Technical Analysis The report-generation workflow instructs the agent to replace template placeholders directly, but it does not require contextual escaping, sanitization, schema validation, or safe DOM construction. The affected placeholders appear in several distinct parser contexts: - HTML text and title contexts, such as `CURRENT_ROLE` and `USER_NAME` - Raw HTML contexts, such as `TASK_ANALYSIS` and recommendation sections - JavaScript contexts, such as `SCORE_CHART_JS` and `COMPETENCY_RADAR_JS` A single generic replacement operation is unsafe across these contexts. For example, text containing HTML markup could terminate its surrounding element and inject a new element with an event ...[truncated 2024 chars]
Remediation
View remediation
`, `"`, and `'` for HTML text and attribute contexts. - Do not use one generic replacement function for HTML and JavaScript contexts. 2. Treat user-provided fields exclusively as text: - Insert them using `textContent` when constructing DOM elements. - Never concatenate profile fields or task descriptions into raw HTML. 3. Replace model-generated HTML fragments with structured data: - Have the model return validated JSON objects for tasks, recommendations, plans, and resources. - Render those objects through fixed, trusted templates. - If rich HTML is unavoidable, sanitize it with a strict allowlist that rejects scripts, event-handler attributes, dangerous URLs, iframes, and active embedded content. 4. Remove generated JavaScript placeholders: - Keep all chart initialization code static. - Pass only validated numeric arrays and fixed labels to that code. - Serialize data with a safe JSON encoder rather than manual string interpolation. - Escape `<` as `\u003c` when embedding serialized JSON inside an HTML script element. 5. Validate values against strict schemas: - Risk and competency scores must be finite numbers within their expected ranges. - CSS classes must come from fixed allowlists such as `low`, `medium`, `high`, and `critical`. - Dates and experience values must follow predefined formats. 6. Add a restrictive Content Security Policy. Prefer a design that permits only local, reviewed scripts and blocks inline event handlers and unexpected network destinations. 7. Add automated security tests using payloads that attempt to break out of: - HTML text nodes - Table cells - Element attributes - JavaScript strings - Script elements ]]>

T08 · Insecure Dependencies

Warning
Location
assets/report_template.html:7
Finding

Remote Chart Library Executes Without Subresource Integrity Protection

Content
View full analysis
``` ### Technical Analysis Every generated report loads and executes Chart.js from the jsDelivr content delivery network. Although the dependency specifies version `4.4.0`, the script element does not include a Subresource Integrity hash. Consequently, the browser trusts the JavaScript returned by the remote CDN at report-viewing time. The reviewed project package does not contain the effective dependency payload and cannot guarantee that the retrieved bytes are identical to the version that was originally assessed. This also conflicts with the statement in `SKILL.md` that the report is self-contained. Opening the report requires a third-party network request and exposes connection metadata to the CDN. ### Attack Path 1. The Skill creates an HTML career report containing the remote script element. 2. A recipient opens the report while connected to the network. 3. The browser requests the Chart.js resource from jsDelivr. 4. If the CDN, upstream package, delivery path, or referenced artifact is compromised or substituted, the browser receives attacker-controlled JavaScript. 5. Because no integrity hash is present, the browser does not reject modified content. 6. The remote script executes within the generated report's browser context. ### Impact Assessment A compromised dependency can execute JavaScript with the same browser-level access as the report itself. Potential impact includes: - Reading and modifying career-profile information displayed in the report - Changing scores or recommendations - Exfiltrating report content through outbound requests - Displaying malicious links or deceptive interfaces - Tracking report viewers and collecting connectio ...[truncated 168 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list is broad enough to match many ordinary career-related queries, which can cause the skill to activate outside the user's explicit intent. This increases the chance of unsolicited profile collection, career advice injection into unrelated conversations, or accidental invocation over more appropriate skills, especially because the skill appears designed to generate detailed personalized planning outputs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list is very broad and includes common career-related phrases, which can cause the skill to activate in routine conversations that do not require this workflow. Because the skill then solicits detailed personal and compensation information and may generate files, unintended invocation increases privacy and consent risk even without malicious intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The 'When to Use' guidance is open-ended and lacks clear exclusion criteria, so the skill may be invoked for broad discussions about careers or AI rather than explicit planning requests. In this skill's context, ambiguous activation is more dangerous because later phases ask for sensitive personal details and create a personalized artifact.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill requests sensitive data including city, salary range, management history, and detailed career background without a prior user-facing warning explaining why the information is requested or that it is optional. This creates a privacy and informed-consent issue, especially because compensation and career-history data can be highly sensitive and identifiable when combined.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction 'All communication with the user is in Chinese (简体中文)' forces a specific language for all interactions. Under the policy, language restrictions should either be opt-in or clearly justified as region-specific; neither is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The HTML document is explicitly marked with lang="zh-CN", and the visible report content is predominantly in Chinese. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is clearly documented and justified, which is not present in this file.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template imports Chart.js directly from a public CDN, which causes client-side execution of third-party code whenever the report is opened. If the CDN asset is tampered with, swapped, blocked, or unexpectedly changed, the generated report could execute untrusted JavaScript in the viewer's browser and compromise report integrity or user privacy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill instructs the agent to write a personalized HTML report to the workspace and deliver it, but it does not require a clear user-facing notice or consent before creating the file. While lower impact than direct data exfiltration, silent artifact creation can surprise users and persist sensitive personal analysis longer than expected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains natural-language content exclusively in Chinese, and there is no indication that the skill or reference is region-specific or that users may choose another language. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file title and all instructional content are written exclusively in Chinese, with no indication that the skill is intentionally region-specific or that users may choose another language. Under the policy, language constraints should be optional or explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.