T09 · Insecure Skill Coding Practices
- Location
scripts/llm_client.py:37- Finding
Unrestricted Model Endpoint Can Receive API Credentials and Sensitive Recruitment Data
- Content
View full analysis
str: return f"{self.base_url.rstrip('/')}/{self.chat_completions_path.lstrip('/')}" ``` ```python user_payload = { "candidate_id": candidate_id, "candidate_id_instruction": "Return exactly this candidate_id in the top-level candidate_id field.", "output_language": evaluation_config.get("output_language"), "role_family_override": evaluation_config.get("role_family_override"), "seniority_override": evaluation_config.get("seniority_override"), "scoring_weights": evaluation_config.get("weights"), "enterprise_hiring_calibration": [ "Score for enterprise recruiting judgment, not academic ranking or resume polish alone.", "Education is important, and papers or competitions can support technical depth, but they should not outweigh concrete project delivery evidence when the project is technically plausible and has visible real-world effects.", "For projects, weigh scenario constraints, personal ownership, implementation details, production/pilot/customer delivery status, measurable impact, scale, cost, quality, efficiency, reliability, and post-launch iteration.", "When no JD is provided, still distinguish landed enterprise projects, pilot delivery, PoC, academic research, coursework, and vague claims; use holistic judgment without rigid caps.", "When JD is provided, prioritize JD-relevant landed projects and technology fit over impressive but unrelated academic or competition signals.", "Do not infer missing facts; use deductions and interview validation points when delivery status, personal contribution, or metrics a ...[truncated 2618 chars]- Remediation
View remediation
