Back to skill

Security audit

Swelist

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its job-search purpose, but it asks agents to read a local profile file and handles resume/application data with unclear consent and persistence boundaries.

Review before installing. Use an explicit tracker database path instead of letting the agent read a broad local profile, confirm before tracker init/add/update/export operations, and redact resumes or background details before using jobgpt. Prefer installing a pinned, reviewed swelist version because the artifact installs a mutable external package.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:193
Finding

Unnecessary Access to the Agent Profile

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 193–201
Vulnerability Type: Least-privilege violation through access to unrelated local configuration
Risk Level: Medium

Relevant Code:

markdown
Local SQLite tracker for job applications synced from Gmail.

**Before invoking any tracker command, read `~/.claude/profile.md`:**

1. Check `Integrations > Tracker Backend` — if `tracker_backend` is `notion`,
   the tracker subcommand is not applicable; use the `application-manager` skill instead.
2. If `tracker_backend` is `sqlite` (or blank, defaulting to sqlite for local use),
   read `SQLite DB path` from profile.md. Use that value as `--db PATH`.
   Fall back to `~/.offerplus/applications.db` only if the field is blank.

Technical Analysis

The Skill requires the agent to read the entire ~/.claude/profile.md file before every tracker command. This file is outside the project and may contain unrelated integration settings, local paths, preferences, or other persistent agent configuration.

The tracker only needs a database path and, optionally, a backend identifier. Reading a general-purpose agent profile therefore exceeds the minimum filesystem privileges required to add, update, query, or export records from a local SQLite database.

Although the instructions do not explicitly direct the agent to transmit the profile, making the profile part of the Skill's execution context unnecessarily exposes its contents to the agent and any downstream command-generation process.

Attack Path

  1. A user asks the agent to perform a tracker operation.
  2. The Skill instructs the agent to open ~/.claude/profile.md.
  3. The agent reads the whole profile to resolve tracker_backend and the SQLite path.
  4. Unrelated configuration contained in that profile enters the active execution context.
  5. That information could be exposed through logging, model context retention, accidental output, or a s ...[truncated 533 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not require automatic access to ~/.claude/profile.md.
  • Accept the tracker database path through an explicit --db argument or a dedicated environment variable.
  • Use ~/.offerplus/applications.db when the user does not provide a path.
  • If backend discovery is essential, ask for explicit user consent before reading external configuration.
  • Retrieve only the required fields through a narrowly scoped configuration interface rather than reading a general-purpose profile.
  • Validate user-supplied database paths and clearly display the selected path before performing write operations.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:36
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 36–42 and 112–117
Vulnerability Type: Mutable and unverifiable third-party dependency
Risk Level: Medium

Relevant Code:

yaml
install:
  - id: uv
    kind: uv
    package: swelist
    bins: ["swelist"]
    label: "Install swelist (uv)"
markdown
## Installation

``` bash
pip install swelist
text

### Technical Analysis

The installation configuration and manual installation command identify the package only as `swelist`, without a fixed version or integrity hash. As a result, installation resolves whichever release the package index currently considers appropriate.

The Skill metadata declares version `0.1.9`, but that declaration does not constrain the package manager to install the corresponding release. The repository contains only `SKILL.md`; it does not include the package source, a lockfile, a checksum, or other material that would allow the installed executable to be verified against the audited artifact.

This creates a supply-chain trust gap. A future compromised, malicious, or behaviorally incompatible release could be installed without any change to the reviewed Skill.

### Attack Path

1. An agent or user activates the Skill installation process.
2. `uv` or `pip` resolves the unversioned `swelist` package from the configured package index.
3. The package index supplies the latest compatible release rather than a specifically audited artifact.
4. Installation hooks or subsequent CLI execution run code from that mutable external package.
5. If the resolved release is compromised, its code executes with the privileges of the installing user.

This is a conditional supply-chain exploitation path. The audit found no evidence that the current `swelist` package is malicious.

### Impact Assessment

A compromised dependency could potentially read or modify files available to the user, access process environment 
...[truncated 313 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to the reviewed release, such as swelist==0.1.9, in every installation path.
  • Ensure the metadata version and installed package version cannot diverge.
  • Use a lockfile or hash-verified installation, such as package-manager hash enforcement.
  • Publish and verify cryptographic checksums or signed release artifacts.
  • Prefer including auditable source code in the Skill package or linking the package to a specific reviewed source commit.
  • Run the dependency in a restricted environment with minimal filesystem, environment-variable, and network access.
  • Establish a dependency-update review process before changing the pinned version.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:528
Finding

Resume and Candidate Data Sent to OpenAI Without Explicit Transmission Consent

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 528–560 and 601–620
Vulnerability Type: Insufficient disclosure and control for external transmission of personal data
Risk Level: Medium

Relevant Code:

markdown
### why-company

Generate a compelling answer to "Why do you want to work at [Company]?"

``` bash
jobgpt why-company "Company Name" --background "Your background"

Options:

  • --background: Your background summary (optional, recommended)
  • --model: OpenAI model to use (default: gpt-4o)
  • --copy: Copy output to clipboard (flag)
text

```markdown
### behavioral

Generate a STAR-format answer to a behavioral interview question.

``` bash
jobgpt behavioral "Question here" [--resume path/to/resume.txt]

Parameters:

  • question (positional, required): The behavioral interview question

Options:

  • --resume: Path to resume text file (optional)
  • --model: OpenAI model to use (default: gpt-4o)
  • --copy: Copy output to clipboard (flag)

Example:

bash
jobgpt behavioral "Describe your biggest failure and how you learned from it" --resume resume.txt --copy
text

```markdown
## Execution Guarantees

-   Requires OpenAI API key (set via `OPENAI_API_KEY` environment variable)
-   No persistent storage
-   Safe for repeated execution
-   Deterministic given identical input (within model capabilities)

## Environment Requirements

-   Python 3.8+
-   OpenAI API key (`OPENAI_API_KEY`)
-   Internet access for API calls

Technical Analysis

The jobgpt functionality calls the OpenAI API and accepts a background summary or the path to a resume text file. Generating a model response from that material necessarily requires submitting relevant prompt content to the external model service.

Resumes and candidate backgrounds commonly contain personal information such as names, contact deta ...[truncated 1784 chars]

Remediation
View remediation

Remediation Suggestions

  • Display a clear warning that questions, background information, and resume content will be sent to OpenAI.
  • Require explicit user confirmation before reading or transmitting any resume file.
  • Show the selected file path and intended destination before transmission.
  • Provide a local redaction step for names, contact information, addresses, identifiers, secrets, and confidential employer data.
  • Send only the portions of a resume needed for the requested answer.
  • Restrict file access to user-selected regular files and reject unexpected paths, symbolic-link escapes, and oversized inputs.
  • Document the relevant third-party privacy, retention, and data-processing implications.
  • Replace the ambiguous “No persistent storage” claim with precise language distinguishing local storage from external API processing.
  • Provide a local-only alternative when users do not consent to external processing.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill claims there is 'No JSON or structured serialization,' but elsewhere documents JSON output for tracker commands. This mismatch can cause an agent to mis-handle sensitive application data, incorrectly parse outputs, or route machine-readable data into unintended downstream automation, increasing the chance of privacy leaks or unsafe actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The execution guarantees say 'No side effects' and 'No persistent storage,' but the tracker commands explicitly create and modify a local SQLite database. Agents relying on those guarantees may invoke state-changing commands under a read-only assumption, causing unauthorized local data creation or modification and breaking user expectations around persistence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The tracker commands modify persistent local state, but the surrounding skill guidance does not prominently warn users or agents that invocation will create or alter a SQLite database. In agent workflows, insufficient disclosure of side effects can lead to unintended writes, silent accumulation of personal job-search data, and unsafe automation behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Line L193 explicitly states the tracker is 'synced from Gmail,' which implies email access or synchronization behavior. The surrounding documented behavior describes only local SQLite operations and DB path selection, so this is an active contradiction in the documentation rather than a mere omission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The jobgpt section states that it uses the OpenAI API but does not clearly warn that prompts, optional resume file contents, and other user-provided material may be transmitted to a third-party service. This is dangerous because users or agents may send sensitive personal, educational, or employment information off-device without informed consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.