Back to skill

Security audit

Job Application

Security checks for vulnerabilities and agentic risk

Overview

This skill locally creates job-application documents from profile and job data, with no evidence of hidden submission, exfiltration, or persistence beyond user-configured profile and output folders.

Install only if you are comfortable giving the skill access to the profile directory you configure and allowing it to write generated applications to the chosen output directory. Use fictional data for tests, keep real profile data outside the installed skill folder as documented, and render PDFs only from generated or trusted .tex files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The supplied code chunk has a narrower and materially different function than the declared description. It suggests which profile elements are relevant to a job by scoring keyword overlap and writing a JSON result. It does not draft tailored job-application materials, produce narrative documents, generate cover letters, create plain-text applications, or perform PDF rendering. While this behavior could support a larger application-generation pipeline, this specific code chunk only implements content selection, so the declared purpose overstates what the code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a content-generation and optional PDF-rendering skill for job applications. The actual code chunk performs a much narrower and different task: it prepares an output directory on the local filesystem based on a validated slug. While this could be a supporting utility for a larger application workflow, this code by itself does not implement the stated primary capabilities of drafting tailored materials or rendering PDFs. Therefore the supplied description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.en.md (reported line 94)May include surrounding context.

md
For projects created through the candidate's own company, use `own_company` with a suitable visible label such as `Own company`. If these fields are absent, the existing project subtitle is rendered on its own.

The skill does not automatically send or publish applications. External delivery always requires explicit authorization for the specific destination.

## Development with OpenSpec

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill documentation indicates access to environment variables, filesystem reads/writes, and shell execution, but it does not declare an explicit tool scope such as permissions or allowed-tools. This weakens the trust boundary for a skill that handles private profile data and generates files, because an agent may grant broader capabilities than a reviewer expects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code defaults to German phrases ("Guten Tag," and "Mit freundlichen Grüßen") when the user does not provide values. This imposes a specific language choice in generated content without offering an explicit opt-in or locale selection, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
84% confidence
Finding

This code invokes an external binary (pdflatex) on .tex files taken from a user-specified directory. Even though subprocess.run is used without a shell and the executable path comes from shutil.which, LaTeX itself can process attacker-controlled input and has a long history of dangerous primitives such as reading local files, excessive resource consumption, and, in some configurations, command execution via TeX features or package behaviors. In the context of a job-application skill that renders generated documents, this becomes more dangerous because the source .tex content may be influenced by untrusted profile/job data and the script executes the renderer locally on the operator's machine.

Content

Scanner excerpt · scripts/render_application.py (reported line 19)May include surrounding context.

python
]
    outputs = []
    for pass_number in (1, 2):
        completed = subprocess.run(
            command,
            cwd=source.parent,
            check=False,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This JSON content uses German-only natural-language fields such as the subtitles and descriptions, with no indication that the skill is region-specific or that users can opt into the locale. Under the policy, language or locale constraints should either offer user choice or be clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This JSON contains natural-language profile fields such as period, title context, subtitle, and descriptions entirely in German. Under the stated policy, forcing a specific language without documented user opt-in can be a locale-policy issue even in config/data files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This JSON contains user-facing text fields such as title, context_label, and description entirely in German. Because the file does not indicate that the content is intentionally region-specific or that users can choose a language, it may conflict with language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The title, context_label, and description in this entry are written only in German. Without a stated regional scope or multilingual option, this can be interpreted as forcing a specific language for user-visible content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The JSON content is entirely fixed in German, including company metadata, salutation, body paragraphs, and closing. For a reusable skill artifact, this imposes a specific language/locale without any opt-in or justification, which matches the language-policy concern described by SQP-3.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The content is entirely specified in German, indicating a fixed language choice in the skill artifact. For a general-purpose skill artifact, this can violate language/locale policy when no user choice or justification for the locale is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest-like JSON explicitly sets the language to "de", which is a natural-language locale constraint. Under the policy rule, locale restrictions should either offer user choice or be clearly justified as region-specific; this file provides neither.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The helper creates parent directories and writes arbitrary text to the supplied path, which is a safety-relevant filesystem modification. In this file there is no confirmation prompt, user-facing log message, or explanatory comment/docstring disclosing that behavior, and the output location is influenced by environment configuration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code performs a file write to the path provided by --output, but there is no confirmation prompt, visible log message, or inline warning describing that it will create or overwrite a file. For code files, file writes are safety-relevant operations when they lack any user disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.