Back to skill

Security audit

europass-cv

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Europass CV helper with an optional consent-gated remote import check, not hidden or deceptive behavior.

This is reasonable to install for Europass CV work. Treat real CVs as personal data: use the local build, extract, and schema validation paths when possible, and run check-import.mjs on a real CV only if the person agrees to send it to the Europass/European Commission service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (15)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
2. Generate: `node tools/build-cv.mjs cv.json > cv.xml`. Read stderr: a

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
2. Generate: `node tools/build-cv.mjs cv.json > cv.xml`. Read stderr: a

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
Europass service: `node tools/check-import.mjs cv.xml`. It prints the

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
Europass service: `node tools/check-import.mjs cv.xml`. It prints the

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
Europass service: `node tools/check-import.mjs cv.xml`. It prints the

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · schema/europass-candidate.xsd (reported line 2)May include surrounding context.

text
<?xml version="1.0" encoding="UTF-8"?>
<!--
  Europass Candidate document, namespace http://www.europass.eu/1.0.

  UNOFFICIAL. The European Commission publishes no schema for this format. This one is derived from

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · schema/europass-candidate.xsd (reported line 27)May include surrounding context.

text
<xs:import namespace="http://www.europass_eures.eu/1.0" schemaLocation="europass-eures.xsd"/>

  <!-- ====================================================================== -->
  <!-- Root                                                                     -->
  <!-- ====================================================================== -->

  <xs:element name="Candidate">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · schema/europass-candidate.xsd (reported line 140)May include surrounding context.

text
</xs:complexType>

  <!-- ====================================================================== -->
  <!-- CandidateSupplier and CandidatePerson                                    -->
  <!-- ====================================================================== -->

  <xs:complexType name="CandidateSupplierType">

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill instructs use of a network-capable script (tools/check-import.mjs) that uploads CV XML to an external European Commission service, but the skill metadata does not declare any tool scope or permission boundary for network access. This creates a real data-exfiltration risk because users may process highly sensitive personal data, and an agent/runtime could invoke networked behavior without an explicit capability declaration or consent gate.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The tool explicitly uploads the provided CV XML or PDF to the live Europass importer, which transmits potentially sensitive personal data to an external server outside the local skill boundary. Although this behavior is documented in comments, it still creates a real data-exfiltration/privacy risk because users may expect a local validation/conversion tool and may supply real CVs containing PII.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The markdown includes Accept-Language: it and describes it as the language of validation messages, which implies a specific locale setting. Because the document does not present this as optional, user-selectable, or region-specific, it may conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON manifest-like file sets "language": "en" even though the CV content is largely Italian-specific, and there is no indication that language selection is user-configurable or explicitly justified. Per the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The XML sets languageCode="en" on the candidate profile, which imposes a specific locale in the document content. There is no accompanying indication in this file that the language is selectable, optional, or justified as a region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script sets the candidate profile language to en whenever cv.language is not provided. This imposes a specific locale by default in generated output, and the file does not present this as an explicit user choice or justify why English must be used.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill description says to use the skill to 'check' a Europass CV/XML/PDF for import, suggesting the skill performs that validation itself. This file's actual behavior is to ask the official remote importer what it accepts, making the capability dependent on an external service rather than the skill's own processing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.