Back to skill

Security audit

Public careers board

Security checks for vulnerabilities and agentic risk

Overview

This skill fetches public job listings from disclosed careers endpoints, with network access and optional output writing that are limited and explained.

Install only if you want a Node-based helper that fetches public job-board data from the listed Acxiom and LiveRamp endpoints. Use the documented scripts/cli.mjs entrypoint, review any --out path before running, and ignore the bundled recipe's standalone evidence CLI unless you intentionally want its broader behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

md
reers board and needs the source and coverage stated. The installed command is `scripts/cli.mjs`. A description match does not select this skill, does not run t

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
reers board and needs the source and coverage stated. The installed command is `scripts/cli.mjs`. A description match does not select this skill, does not run t

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
reers board and needs the source and coverage stated. The installed command is `scripts/cli.mjs`. A description match does not select this skill, does not run t

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
`recipe/boards.mjs` is the upstream file. Do not run it as the installed command. Its own CLI writes an evidence file and reads every board. This command reads

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
`recipe/boards.mjs` is the upstream file. Do not run it as the installed command. Its own CLI writes an evidence file and reads every board. This command reads

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill explicitly performs network access and invokes a Node.js CLI, but the manifest does not declare any tool scope such as allowed tools or permissions. That creates a trust gap for agents and policy engines, which may run the skill without clear enforcement boundaries on shell and network behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Importing file-write capability enables persistence of fetched data to local storage, and this capability is in fact used later to save board contents to an evidence JSON file. For a skill whose stated purpose is to return rows and coverage, unexpected local persistence creates unnecessary data retention and side effects that can leak information into the host filesystem or violate least-privilege expectations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module contains a standalone CLI that fetches all configured job boards and writes a local evidence artifact, which exceeds the stated skill behavior of fetching one supported board for return to the caller. Hidden or undocumented capability expansion is dangerous because it broadens data collection and side effects, making the component behave differently than integrators and policy reviewers would expect.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · recipe/boards.mjs (reported line 30)May include surrounding context.

js
};
const ashbyCtx = {
  boardUrl: "https://jobs.ashbyhq.com/liveramp-inc",
  source: "https://api.ashbyhq.com/posting-api/job-board/liveramp-inc",
  fetchedAt: ctx.fetchedAt,
};
const good = { title: "One", externalPath: "/job/A/One_1", locationsText: "Remote" };

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · recipe/boards.public.test.mjs (reported line 12)May include surrounding context.

js
};
const ashbyCtx = {
  boardUrl: "https://jobs.ashbyhq.com/liveramp-inc",
  source: "https://api.ashbyhq.com/posting-api/job-board/liveramp-inc",
  fetchedAt: ctx.fetchedAt,
};
const good = { title: "One", externalPath: "/job/A/One_1", locationsText: "Remote" };

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · recipe/boards.public.test.mjs (reported line 22)May include surrounding context.

js
test("request gate rejects insecure protocols and embedded credentials", () => {
  for (const url of [
    "http://api.ashbyhq.com/posting-api/job-board/liveramp-inc",
    "https://user:secret@api.ashbyhq.com/posting-api/job-board/liveramp-inc",
    "https://api.ashbyhq.com.evil.example/posting-api/job-board/liveramp-inc",
  ]) assert.equal(gateRequest(url).ok, false);

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · recipe/boards.public.test.mjs (reported line 24)May include surrounding context.

js
for (const url of [
    "http://api.ashbyhq.com/posting-api/job-board/liveramp-inc",
    "https://user:secret@api.ashbyhq.com/posting-api/job-board/liveramp-inc",
    "https://api.ashbyhq.com.evil.example/posting-api/job-board/liveramp-inc",
  ]) assert.equal(gateRequest(url).ok, false);
  assert.equal(gateRequest(ashbyCtx.source).ok, true);
});

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The recipe documentation advertises an unrelated external task-help/contact service that is outside the stated purpose of fetching public careers-board data. In a security-sensitive agent ecosystem, this can steer users or downstream agents toward an unnecessary third-party endpoint, creating a social-engineering and trust-boundary risk even though it does not itself execute code.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.