Back to skill

Security audit

Hr Toolkit

Security checks for vulnerabilities and agentic risk

Overview

This HR toolkit mostly provides HR templates, but it also ships an under-disclosed generic local data logger/export tool that could retain sensitive HR information.

Review carefully before installing. The HR template commands are coherent, but the package also includes a generic local storage/export script that can keep employee or candidate details in plaintext logs and may not actually remove records when asked. Avoid entering sensitive HR data unless the publisher documents storage, deletion, permissions, and retention behavior or removes the generic persistence feature.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:5
Finding

Undisclosed Plaintext Persistence and Ineffective Deletion of Potentially Sensitive HR Data

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh, lines 5-8, 31, and 49-57
Vulnerability Type: Plaintext sensitive-data storage and ineffective deletion
Risk Level: Medium

Vulnerable Code

bash
DATA_DIR="${HR_TOOLKIT_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/hr-toolkit}"
DB="$DATA_DIR/data.log"
mkdir -p "$DATA_DIR"
bash
_log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }
bash
cmd_add() {
    echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo "  Added: $*"
    _log "add" "${1:-}"
}

cmd_remove() {
    echo "  Removed: $1"
    _log "remove" "${1:-}"
}

Technical Analysis

The add command writes the complete supplied argument string to the persistent data.log file without encryption, redaction, retention limits, or an explicit user warning. It also records the first argument in history.log.

This project is presented as an HR toolkit whose documented usage includes employee names, job information, onboarding details, and departure circumstances. Consequently, arguments may contain personal or employment-related information. The script does not establish restrictive permissions with umask 077 or explicit chmod operations; resulting access permissions therefore depend on the invoking environment's current umask.

The remove command compounds this problem by printing Removed without modifying data.log. It merely adds another history entry. A user can consequently receive a false indication that an HR record was deleted while the original plaintext record remains stored.

Storage is also not disclosed in the primary skill documentation. The command implementation therefore persists data beyond the immediate operation without presenting retention, consent, deletion, or data-minimization controls.

Attack Path

  1. A user invokes hr-toolkit add with an employee name, role, departure reason, or other HR-related information ...[truncated 1347 chars]
Remediation
View remediation

Remediation Suggestions

  1. Avoid storing command arguments unless persistence is explicitly requested and documented.
  2. Clearly disclose what data is stored, where it is stored, how long it is retained, and how users can delete it.
  3. Establish restrictive permissions before creating storage:
    bash
    umask 077
    mkdir -p -- "$DATA_DIR"
    chmod 700 -- "$DATA_DIR"
    touch -- "$DB" "$DATA_DIR/history.log"
    chmod 600 -- "$DB" "$DATA_DIR/history.log"
    
  4. Minimize log contents. Do not copy employee names or complete command arguments into history logs; record only non-sensitive operational metadata when necessary.
  5. Implement actual deletion in cmd_remove, using a stable record identifier rather than ambiguous text matching. Report success only after verifying that the target record was removed.
  6. Provide commands for listing retained records, defining retention periods, and securely purging stored data where supported.
  7. Consider authenticated encryption if sensitive HR records must be retained, with keys stored separately from the data files.
  8. Add automated tests confirming that deletion removes the intended record and that created directories and files are not accessible to other users by default.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill metadata and documentation present the tool as a narrowly scoped HR assistant, but the finding indicates additional undeclared behaviors such as generic local data logging, file-based add/search/export utilities, and command history storage. In an HR context, hidden persistence and export features are especially risky because users may input sensitive employee or candidate information, creating undisclosed collection, retention, or exfiltration paths.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation guidance 'Use when managing HR processes' is too broad and can cause the skill to trigger in many loosely related situations. Because HR workflows commonly involve highly sensitive personal, employment, and disciplinary data, overbroad invocation increases the chance that the skill is used unnecessarily or receives confidential data outside a well-defined need.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This shell script emits user-facing HR guidance, templates, and instructions almost entirely in Chinese, which effectively forces a specific language for normal use. The file does not offer an alternative language, locale selection, or any documented justification for the language restriction.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest promises HR-focused capabilities such as recruitment process support, onboarding/offboarding handling, policy, handbook, and template library functions. In contrast, the script advertises itself as a 'Multi-purpose utility tool' and exposes only generic commands like add, list, search, export, and status without any HR-specific logic or domain operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script persistently logs user-supplied command arguments to history.log without notice, which can capture sensitive HR-related inputs such as employee names, identifiers, search terms, or termination/onboarding details. In an HR context, silent retention of operational inputs increases privacy and confidentiality risk because local logs may be readable by other processes, users, backups, or support personnel.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The add command writes arbitrary user-provided content into a persistent data file without any warning, which can unintentionally store sensitive HR records or personal data. Because this skill is presented as an HR toolkit, users may reasonably enter employee-related information, making undisclosed persistence materially more dangerous from a privacy and compliance perspective.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code documentation and CLI help present the skill as a broad, generic utility rather than an HR-focused toolkit. This creates an intent mismatch between the skill's declared purpose in the manifest and the code's own user-facing documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This file contains user-facing instructions entirely in Chinese, aside from a few parenthetical English labels, and does not indicate that the skill is intended only for Chinese-speaking users or provide an opt-in language choice. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.