Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md 2. Generate: `node tools/build-cv.mjs cv.json > cv.xml`. Read stderr: a
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed Europass CV helper with an optional consent-gated remote import check, not hidden or deceptive behavior.
This is reasonable to install for Europass CV work. Treat real CVs as personal data: use the local build, extract, and schema validation paths when possible, and run check-import.mjs on a real CV only if the person agrees to send it to the Europass/European Commission service.
Referenced artifact was not completely inspected
2. Generate: `node tools/build-cv.mjs cv.json > cv.xml`. Read stderr: a
Referenced artifact was not completely inspected
2. Generate: `node tools/build-cv.mjs cv.json > cv.xml`. Read stderr: a
Referenced artifact was not completely inspected
Europass service: `node tools/check-import.mjs cv.xml`. It prints the
Referenced artifact was not completely inspected
Europass service: `node tools/check-import.mjs cv.xml`. It prints the
Referenced artifact was not completely inspected
Europass service: `node tools/check-import.mjs cv.xml`. It prints the
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<?xml version="1.0" encoding="UTF-8"?>
<!--
Europass Candidate document, namespace http://www.europass.eu/1.0.
UNOFFICIAL. The European Commission publishes no schema for this format. This one is derived from
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
<xs:import namespace="http://www.europass_eures.eu/1.0" schemaLocation="europass-eures.xsd"/>
<!-- ====================================================================== -->
<!-- Root -->
<!-- ====================================================================== -->
<xs:element name="Candidate">
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
</xs:complexType>
<!-- ====================================================================== -->
<!-- CandidateSupplier and CandidatePerson -->
<!-- ====================================================================== -->
<xs:complexType name="CandidateSupplierType">
The skill instructs use of a network-capable script (tools/check-import.mjs) that uploads CV XML to an external European Commission service, but the skill metadata does not declare any tool scope or permission boundary for network access. This creates a real data-exfiltration risk because users may process highly sensitive personal data, and an agent/runtime could invoke networked behavior without an explicit capability declaration or consent gate.
The tool explicitly uploads the provided CV XML or PDF to the live Europass importer, which transmits potentially sensitive personal data to an external server outside the local skill boundary. Although this behavior is documented in comments, it still creates a real data-exfiltration/privacy risk because users may expect a local validation/conversion tool and may supply real CVs containing PII.
The markdown includes Accept-Language: it and describes it as the language of validation messages, which implies a specific locale setting. Because the document does not present this as optional, user-selectable, or region-specific, it may conflict with language/locale policy expectations.
This JSON manifest-like file sets "language": "en" even though the CV content is largely Italian-specific, and there is no indication that language selection is user-configurable or explicitly justified. Per the policy, forcing a specific language without user opt-in can be a natural-language policy violation.
The XML sets languageCode="en" on the candidate profile, which imposes a specific locale in the document content. There is no accompanying indication in this file that the language is selectable, optional, or justified as a region-specific requirement.
The script sets the candidate profile language to en whenever cv.language is not provided. This imposes a specific locale by default in generated output, and the file does not present this as an explicit user choice or justify why English must be used.
The skill description says to use the skill to 'check' a Europass CV/XML/PDF for import, suggesting the skill performs that validation itself. This file's actual behavior is to ask the official remote importer what it accepts, making the capability dependent on an external service rather than the skill's own processing.
No suspicious patterns detected.