Back to skill

Security audit

PM Interview Grill

Security checks for vulnerabilities and agentic risk

Overview

This is a PM interview coaching skill made of Markdown prompts and reference material, with no executable code or hidden data movement found.

Before installing, note that the skill is Chinese-first and may activate on general PM interview requests. If you use the resume/project grilling mode, only share resume or project details you are comfortable giving to your agent. The publisher should replace the absolute file:// reference links with relative bundled paths.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (13)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · README.md (reported line 101)May include surrounding context.

2. Antigravity Agent 安装

bash
mkdir -p ~/.gemini/config/skills
git clone https://github.com/isdou/pm-interview-grill.git ~/.gemini/config/skills/pm-interview-grill

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · README.md (reported line 102)May include surrounding context.

2. Antigravity Agent 安装

bash
mkdir -p ~/.gemini/config/skills
git clone https://github.com/isdou/pm-interview-grill.git ~/.gemini/config/skills/pm-interview-grill

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
98% confidence
Finding

The skill embeds a file:// URI pointing into the agent's local configuration directory (~/.gemini/config/skills/...). References to local config paths can encourage the agent to access sensitive local files or reveal filesystem structure, which is especially risky if path-following behavior or file reading is supported elsewhere in the platform. Even if these files are intended as local references, exposing absolute internal paths leaks environment details and can normalize privileged local-file access.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
## 📚 参考资料库

本 Skill 包含以下详细参考指南,位于 `references/` 目录中:
- [PM 核心思维框架库](file:///Users/suxiaohan/.gemini/config/skills/pm-interview-grill/references/pm_frameworks.md):包含 CIRCLES, STAR, AARM, BUS, DIGS 等面试金牌框架。
- [大厂 PM 高频真题库](file:///Users/suxiaohan/.gemini/config/skills/pm-interview-grill/references/pm_question_bank.md):涵盖 Product Design, Metrics, Strategy, Behavioral 四大板块题目。
- [评估 Rubric 指南](file:///Users/suxiaohan/.gemini/config/skills/pm-interview-grill/references/coaching_rubric.md):多维度评分标准与追问策略指南。

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
98% confidence
Finding

This line exposes another absolute file:// reference into the local agent configuration tree. Such references can disclose host-specific path information and may prompt unsafe access to locally stored skill data or neighboring files if an attacker can manipulate follow-up behavior or exploit path handling weaknesses.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
本 Skill 包含以下详细参考指南,位于 `references/` 目录中:
- [PM 核心思维框架库](file:///Users/suxiaohan/.gemini/config/skills/pm-interview-grill/references/pm_frameworks.md):包含 CIRCLES, STAR, AARM, BUS, DIGS 等面试金牌框架。
- [大厂 PM 高频真题库](file:///Users/suxiaohan/.gemini/config/skills/pm-interview-grill/references/pm_question_bank.md):涵盖 Product Design, Metrics, Strategy, Behavioral 四大板块题目。
- [评估 Rubric 指南](file:///Users/suxiaohan/.gemini/config/skills/pm-interview-grill/references/coaching_rubric.md):多维度评分标准与追问策略指南。

---

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
98% confidence
Finding

This is a third absolute local-path reference into ~/.gemini/config, reinforcing a pattern of exposing internal filesystem locations. Repeated local config references increase the likelihood of unintended file disclosure, environment fingerprinting, or abuse of any tool/runtime capability that can dereference file:// URIs.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
本 Skill 包含以下详细参考指南,位于 `references/` 目录中:
- [PM 核心思维框架库](file:///Users/suxiaohan/.gemini/config/skills/pm-interview-grill/references/pm_frameworks.md):包含 CIRCLES, STAR, AARM, BUS, DIGS 等面试金牌框架。
- [大厂 PM 高频真题库](file:///Users/suxiaohan/.gemini/config/skills/pm-interview-grill/references/pm_question_bank.md):涵盖 Product Design, Metrics, Strategy, Behavioral 四大板块题目。
- [评估 Rubric 指南](file:///Users/suxiaohan/.gemini/config/skills/pm-interview-grill/references/coaching_rubric.md):多维度评分标准与追问策略指南。

---

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 94)May include surrounding context.

1. Codex & 通用 Agent CLI 安装

bash
mkdir -p ~/.agents/skills
git clone https://github.com/isdou/pm-interview-grill.git ~/.agents/skills/pm-interview-grill

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 108)May include surrounding context.

3. Claude Code 安装

bash
mkdir -p ~/.claude/skills
git clone https://github.com/isdou/pm-interview-grill.git ~/.claude/skills/pm-interview-grill

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger example "帮我准备产品经理面试" is a broad natural-language request that could easily appear in ordinary conversation, not just as an intentional invocation of this specific skill. The README does not provide limiting conditions, scope constraints, or negative examples to clarify when this skill should activate versus when a general assistant response would be more appropriate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger condition includes a broad natural-language phrase ('需要 PM 面试指导时触发'), which can cause the skill to activate in loosely related contexts. Over-broad activation increases the chance the skill is invoked when the user did not intend it, potentially exposing internal prompting, altering assistant behavior, or interfering with safer higher-priority workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The prompt hard-codes a Chinese-only welcome and interaction flow without giving the user a language choice or honoring the user's language. This can cause accessibility and usability failures, and may lead users to misunderstand interview guidance or disclose information they did not intend if they cannot fully understand the interaction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire rubric and mandatory instruction language are specified in Chinese, and the text states the AI interviewer '必须' follow these requirements. There is no indication that users can opt into another language or that this is a China-specific or Chinese-language-only skill, which can violate language/locale choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file is entirely written in Chinese and does not indicate any supported language negotiation or locale constraint, so users who trigger the skill in another language may receive unusable guidance. This is primarily an accessibility and reliability issue rather than a classic security flaw, but in agent settings it can still degrade user control and cause misunderstanding of interview coaching content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill description is predominantly written in Chinese and does not state that users may choose another language for interaction. Under the policy, forcing a specific language without user opt-in can be a natural-language policy concern unless the locale restriction is justified and documented.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
SYSTEM_PROMPT.md:1