Back to skill

Security audit

job-hunter-whatsapp

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent job-search helper, but it asks to store sensitive job-search data and API keys locally and create recurring jobs that send updates without enough user-control safeguards.

Review this skill carefully before installing. Only use it in a workspace where storing resumes, job preferences, application status, and API keys is acceptable; avoid plaintext secrets where possible. Do not enable cron jobs or messaging updates unless you have confirmed the exact schedule, destination, content, and a way to pause or delete the automation.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T06 · System Persistence

Warning
Location
SKILL.md:123
Finding

Recurring Cron Jobs Create Cross-Session Persistence Without Defined Lifecycle Controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 123-134
Vulnerability Type: Persistent scheduled task creation
Risk Level: Medium

Vulnerable Code

markdown
## Automation

### Cron Jobs

Set up two cron jobs:

1. **Job Finder** — Daily at user's preferred time (default 9 AM local):
   - Query all APIs, parse new JDs, update tracker
   - `sessionTarget: "isolated"`, `delivery: "announce"`

2. **Status Update** — Daily at user's preferred time (default 11 AM local):
   - Read tracker, compile summary, send to user's messaging channel
   - `sessionTarget: "isolated"`, `delivery: "announce"`

Technical Analysis

The Skill directs the agent to create two recurring cron jobs. These scheduled jobs survive the original interactive run and repeatedly initiate isolated sessions that read local job-tracking information, contact external job APIs, update stored records, and deliver information through a messaging channel.

Scheduled automation is part of the declared job-search functionality, and the audited text does not establish that it is intended as a covert backdoor. However, the instructions do not require explicit confirmation immediately before creating the jobs, define an expiration time, or provide procedures to enumerate, pause, or remove existing schedules. Consequently, a user may unintentionally authorize persistent processing after expecting the original session to end.

Attack Path

  1. A user activates the Skill to configure job-search automation.
  2. The agent follows the instruction to create the Job Finder and Status Update cron jobs.
  3. The scheduled entries persist beyond the initiating session.
  4. At their configured times, isolated sessions read local configuration and job-tracking data.
  5. The sessions contact configured external job services and send summaries through the user's messaging channel.
  6. This activity continues indefinitely unless the underlying s ...[truncated 726 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit, informed user confirmation immediately before creating each scheduled task.
  2. Display the exact schedule, task purpose, files accessed, external services contacted, and messaging destination before confirmation.
  3. Default to one-time execution unless recurring automation is specifically requested.
  4. Assign a finite expiration date or maximum run count to every schedule by default.
  5. Provide documented commands to list, pause, resume, and permanently delete all schedules created by the Skill.
  6. Prevent duplicate schedules by checking for an existing task before creating another one.
  7. Apply least privilege to isolated sessions, limiting them to the required project files, API hosts, and messaging destination.
  8. Record task creation, execution, failure, and deletion in an auditable local log without exposing credentials or unnecessary personal data.

T08 · Insecure Dependencies

Note
Location
scripts/extract_resume.mjs:1
Finding

Unpinned Third-Party PDF Processing Dependency

Content
View full analysis

Vulnerability Details

File Location: scripts/extract_resume.mjs, lines 1-10
Vulnerability Type: Unpinned third-party dependency and non-reproducible installation
Risk Level: Low

Vulnerable Code

javascript
#!/usr/bin/env node
/**
 * Job Hunter - PDF Resume Text Extractor
 * Extracts text from a PDF resume using pdfjs-dist.
 * 
 * Usage: node extract_resume.js <input.pdf> <output.md>
 * Requires: npm install pdfjs-dist
 */

import fs from 'fs';
import { getDocument } from 'pdfjs-dist/legacy/build/pdf.mjs';

Technical Analysis

The script instructs users to install pdfjs-dist without specifying an exact version. The audited project contains no documented version constraint, lockfile, or package integrity value. Running npm install pdfjs-dist therefore resolves a package version according to the registry state at installation time rather than a version reviewed together with this project.

This prevents reproducible dependency installation and increases exposure to future supply-chain compromise, malicious package publication, or an incompatible release. Because the dependency parses user-supplied PDF resumes, defects in a subsequently resolved version may also be reachable through crafted PDF content.

No evidence was found that the currently named pdfjs-dist package is malicious, that dependency confusion is actively being attempted, or that this project executes an intentionally harmful dependency. The finding concerns the unsafe, mutable dependency-resolution process.

Attack Path

  1. A user follows the documented prerequisite and runs npm install pdfjs-dist.
  2. The package manager resolves the dependency version available under the package name at that time.
  3. If the resolved release or one of its transitive dependencies has been compromised or contains an exploitable defect, its installation or runtime code enters the local environment.
  4. The user invo ...[truncated 954 chars]
Remediation
View remediation

Remediation Suggestions

  1. Add a package.json that pins pdfjs-dist to a reviewed exact version rather than a floating range.
  2. Generate and commit a package-manager lockfile containing resolved versions and integrity hashes.
  3. Replace the installation instruction with npm ci so installations reproduce the reviewed dependency tree.
  4. Review package provenance, release history, maintainers, integrity metadata, and known security advisories before selecting the pinned version.
  5. Use automated dependency scanning and establish a controlled process for reviewing and updating pinned versions.
  6. Process untrusted PDFs in a restricted environment with minimal file-system access, no unnecessary credentials, and network access disabled where practical.
  7. Apply PDF size and page-count limits to reduce denial-of-service exposure from malformed or excessively large documents.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes broad phrases like "find jobs," "job search," "show jobs," and "status," which can overlap with ordinary conversation and cause unintended invocation of the skill. In this skill's context, accidental activation is more concerning because the skill can read/write local files, store personal profile data, and initiate automated workflows based on ambiguous requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs collecting and storing sensitive profile data, resume contents, and API credentials in local files without any explicit privacy notice, consent flow, access controls, or retention guidance. This is dangerous because resumes and job-search profiles often contain personally identifiable information, employment history, salary preferences, and secrets that could be exposed through workspace access, logs, backups, or other skills.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill describes scheduled background jobs and outbound messaging updates without a clear warning that personal job-search data will be periodically processed and transmitted to a messaging channel. In context, this can expose sensitive information such as employers of interest, application status, salary details, and location preferences through unintended notifications, shared devices, or misconfigured channels.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/apis.md (reported line 72)May include surrounding context.

md
Register: https://developer.adzuna.com (free tier)

Endpoint: `https://api.adzuna.com/v1/api/jobs/{country}/search/{page}`

Country codes: `in` (India), `us`, `gb`, `ca`, `au`, `de`, etc.

Static analysis

No suspicious patterns detected.