Back to skill

Security audit

persian-resume

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Persian resume generator that uses local scripts to create and validate user-requested PDF or DOCX resumes without hidden persistence, credential access, or network execution.

Install this when you specifically want Persian/RTL resume generation. Expect it to process resume data from local JSON and create or validate local PDF/DOCX files; review generated resumes for factual accuracy because the skill instructs the agent not to invent missing career details but cannot independently verify them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared purpose emphasizes resume generation, but the content also directs validation of generated files and inspection of resume data, implying filesystem access and auditing behavior not clearly disclosed in the metadata. This mismatch can cause the skill to be invoked in contexts where users or orchestrators do not expect file inspection, increasing the chance of over-broad data access or unsafe routing.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: persian-resume
description: >-
  Generate professional Persian (RTL) resumes/CVs that render correctly with mixed
  Persian-English content. Use this skill whenever the user asks to create,
  rewrite, polish, or transform a Persian resume/CV, or when a resume contains
  mixed Persian and English/technical content that must remain readable and
  correctly ordered in RTL. Also trigger when the user provides career info in
  any language and wants a professional Persian CV, or asks to fix RTL/bidi
  issues in a Persian resume. This skill is NOT for general Persian documents —
  use persian-documents for repor

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

json
{
  "name": "علی احمدی",
  "title": "توسعه‌دهنده Full-Stack",
  "email": "ali@example.com",
  "phone": "+98 912 123 4567",
  "location": "تهران، ایران",

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

json
{
  "name": "علی احمدی",
  "title": "توسعه‌دهنده Full-Stack",
  "email": "ali@example.com",
  "phone": "+98 912 123 4567",
  "location": "تهران، ایران",

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 163)May include surrounding context.

json
{
  "name": "علی احمدی",
  "title": "توسعه‌دهنده Full-Stack",
  "email": "ali@example.com",
  "phone": "+98 912 123 4567",
  "location": "تهران، ایران",

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 164)May include surrounding context.

json
{
  "name": "علی احمدی",
  "title": "توسعه‌دهنده Full-Stack",
  "email": "ali@example.com",
  "phone": "+98 912 123 4567",
  "location": "تهران، ایران",

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/resume-data-schema.md (reported line 20)May include surrounding context.

json
{
  "name": "علی احمدی",
  "title": "توسعه‌دهنده Full-Stack",
  "email": "ali@example.com",
  "phone": "+98 912 123 4567",
  "location": "تهران، ایران",

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/resume-data-schema.md (reported line 28)May include surrounding context.

json
{
  "name": "علی احمدی",
  "title": "توسعه‌دهنده Full-Stack",
  "email": "ali@example.com",
  "phone": "+98 912 123 4567",
  "location": "تهران، ایران",

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/resume-data-schema.md (reported line 47)May include surrounding context.

json
{
  "name": "علی احمدی",
  "title": "توسعه‌دهنده Full-Stack",
  "email": "ali@example.com",
  "phone": "+98 912 123 4567",
  "location": "تهران، ایران",

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/resume-data-schema.md (reported line 55)May include surrounding context.

json
{
  "name": "علی احمدی",
  "title": "توسعه‌دهنده Full-Stack",
  "email": "ali@example.com",
  "phone": "+98 912 123 4567",
  "location": "تهران، ایران",

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/resume-data-schema.md (reported line 94)May include surrounding context.

json
{
  "name": "علی احمدی",
  "title": "توسعه‌دهنده Full-Stack",
  "email": "ali@example.com",
  "phone": "+98 912 123 4567",
  "location": "تهران، ایران",

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/resume-data-schema.md (reported line 96)May include surrounding context.

json
{
  "name": "علی احمدی",
  "title": "توسعه‌دهنده Full-Stack",
  "email": "ali@example.com",
  "phone": "+98 912 123 4567",
  "location": "تهران، ایران",

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/resume-data-schema.md (reported line 97)May include surrounding context.

json
{
  "name": "علی احمدی",
  "title": "توسعه‌دهنده Full-Stack",
  "email": "ali@example.com",
  "phone": "+98 912 123 4567",
  "location": "تهران، ایران",

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/resume-data-schema.md (reported line 114)May include surrounding context.

json
{
  "name": "علی احمدی",
  "title": "توسعه‌دهنده Full-Stack",
  "email": "ali@example.com",
  "phone": "+98 912 123 4567",
  "location": "تهران، ایران",

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/generate_resume.py (reported line 618)May include surrounding context.

python
in ["website", "github", "linkedin", "portfolio"]:
            if c.get(fld):
                contact.append(c[fld])
        if contact:
            self._para("  |  ".join(contact), size=9, alignment="center")
        if target:
            self._para(f"هدف شغلی: {target}", size=10, alignment="center", italic=True)
        if c.get("summary"):
            self._heading("خلاصه حرفه‌ای", level=2)
            self._para(c["summary"])

        # Sections in priority order
        order = {"experience": 0, "project": 1, "education": 2,
                 "skills": 3, "certification": 4, "language": 5,
                 "award": 6, "publication": 7, "achievement": 8}
        sections = sorted(data.get("sections", []),
                          key=lambda s: order.get(s.get("type", ""), 99))

        for sec in sections:
            stype = sec.get("type", "")
            title = sec.get("title", "")
            items = sec.get("items", [])
            categories = sec.get("

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description instructs the skill to generate a professional Persian CV whenever the user wants resume help in several broad situations, including when the user provides career info in any language. This imposes a specific language/locale outcome by default rather than clearly requiring the user to opt into Persian output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file uses Persian sample content throughout and the options restrict calendar to persian or gregorian while fonts are limited to Persian-oriented choices. Because the schema does not explicitly offer a general language choice or explain that the skill is intentionally region-specific, it can be read as forcing a specific language/locale without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains natural-language requirements that mandate a specific locale and script presentation, including a Persian font and RTL layout. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless clearly documented as a justified region-specific tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring and generated document settings explicitly define the resume as Persian and RTL, and the CLI description repeats that fixed locale. The policy allows locale constraints only when clearly documented and justified or when the user is offered a choice; this file does not provide an opt-in or configurable language selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstring and usage describe the tool as validating only a generated Persian resume, which is a natural-language locale constraint. Under the policy, forcing a specific language or locale without user opt-in or a clearly documented justification should be flagged.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This is a manifest-like JSON file, so vague trigger review applies. The phrase identifies the skill by name but does not specify activation scope, constraints, or negative examples, which could make invocation matching overly broad in systems that rely on natural-language descriptions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.