Back to skill

Security audit

job-match-priority

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed job-matching skill that reads user-provided resume and job data and writes matching results, with no evidence of hidden code, exfiltration, or persistence abuse.

Before installing, be comfortable with the agent reading the resume/JD files or Feishu table links you provide and writing priority fields or separate result files. Clarify where any reused candidate profile or matching configuration will be stored, and review Feishu updates before using it on shared business tables.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The primary descriptive text is presented as Chinese-only and identifies the skill as dedicated to a specific environment, but there is no statement that users may choose another language or that Chinese is a required locale for compliance or regional operation. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states that the agent will automatically trigger this skill for broad recruiting-related requests such as resume matching, JD matching, and job filtering. Overly broad activation criteria can cause unintended invocation on common user requests, leading the agent to process resumes, preferences, and job data without sufficiently explicit user intent or a narrower routing condition. In this context, the skill handles sensitive employment-related data, which makes accidental activation more consequential.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill title and all operational instructions are presented in Chinese, and the document does not state that language selection is optional or region-specific. Under the language/locale policy, forcing a single language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation explicitly states '全链路 Agent 推理,零脚本' at L016 and repeats '不使用脚本' at L311, suggesting a purely reasoning-based flow without operational side effects. However, the same file defines writing results to Feishu bitables via batch_update and creating new local CSV/Excel output files, which contradicts the no-script/no-automation claim at the intent level.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger condition is very broad ('when the user asks for resume matching, JD matching, or job screening'), which can cause the skill to activate on loosely related recruiting conversations without clear user intent. In a skill that processes resumes, local files, spreadsheets, and remote tables, over-triggering can lead to unnecessary access to sensitive employment data or unintended write operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document's instructions and labels are fully in Chinese, which effectively forces a specific language for users of the skill. Under the policy, locale or language constraints should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file presents all operational rules and user-facing interaction examples entirely in Chinese, including the prescribed agent prompt at L074-L079. The file does not indicate that language is optional, configurable, or limited to a justified region-specific context, which can violate a language/locale policy requiring user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file is written primarily in Chinese and includes English scoring/status terms such as "medium" and "low," but it does not indicate that the skill is intentionally Chinese-only or offer users a language choice. Under the policy rule for language/locale, forcing a specific language without opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file uses Chinese throughout for headings, field names, instructions, and examples, but does not indicate that the skill is Chinese-only or provide an opt-in language choice. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.