Back to skill

Security audit

CV Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a resume and cover-letter generator whose file access, document creation, optional PDF conversion, and dependency use are disclosed and aligned with that purpose.

Install this in a constrained workspace and avoid feeding it unnecessary personal data beyond what is needed for the resume. For stronger supply-chain hygiene, pin and review python-docx and its transitive dependencies before running the documented pip install step.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unbounded Third-Party Dependency Installation

Content
View full analysis
=1.1.2 ``` `SKILL.md:71-75`: ```markdown If `python-docx` is missing, install dependencies first: ```bash python3 -m pip install -r requirements.txt ``` ``` ### Technical Analysis The documented installation procedure directs the user or Agent to install a third-party package from the configured Python package index. The constraint `python-docx>=1.1.2` permits pip to select any current or future release satisfying the minimum version. No exact version, lock file, upper version bound, package hash, or transitive dependency constraints are supplied. Consequently, the dependency graph installed at execution time may differ from the dependency graph reviewed during this audit. The currently declared package is a legitimate public dependency, and the project contains no evidence that it is presently malicious. The security weakness is that a future compromised, malicious, or unexpectedly incompatible release could be selected automatically. Package installation or subsequent import may then execute code under the privileges of the user running pip or the resume generator. ### Attack Path 1. An Agent follows the setup instructions in `SKILL.md`. 2. The Agent executes `python3 -m pip install -r requirements.txt`. 3. pip queries the configured package index and resolves the newest release satisfying `python-docx>=1.1.2`, together with its transitive dependencies. 4. If a permitted future release or one of its resolved dependencies has been compromised, pip installs the affected component without integrity verification. 5. Malicious code may execute during installation or when `generate_resume.py` imports the package. 6. The payload runs with the permissions of the invoking user and can access ...[truncated 633 chars]
Remediation
View remediation
``` 2. Generate and commit a lock file that pins all transitive dependencies rather than only the direct dependency. 3. Record cryptographic hashes for every resolved distribution and enforce them during installation: ```bash python3 -m pip install --require-hashes -r requirements.lock ``` 4. Build the lock file from a trusted package index in a controlled environment. Avoid untrusted extra indexes and dependency sources. 5. Review dependency updates explicitly instead of accepting them automatically. Use automated vulnerability and provenance scanning before updating pinned versions. 6. Prefer an isolated virtual environment or container with least-privilege filesystem and network access when installing dependencies and processing candidate data. 7. Update `SKILL.md` so its installation example uses the reviewed lock file and hash verification rather than the unbounded `requirements.txt`. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs the agent to read local files and run shell commands, including dependency installation and document generation, but it does not declare any explicit tool scope or permission boundaries. This creates an authorization gap where the agent may invoke file and shell capabilities more broadly than intended, increasing the risk of unintended command execution, unsafe package installation, or access to sensitive local data during resume processing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The activation description is broad enough to trigger on many resume, CV, rewriting, translation, and document-conversion requests without clearly stating exclusions or safety boundaries. In a skill that can read files and run shell commands, overbroad routing increases the chance the agent will invoke this skill in situations involving untrusted attachments or unnecessary code execution, expanding exposure beyond the intended use case.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/generate_resume.py (reported line 253)May include surrounding context.

python
if not office:
        return None
    try:
        subprocess.run(
            [office, "--headless", "--convert-to", "pdf", "--outdir", str(docx_path.parent), str(docx_path)],
            check=True,
            stdout=subprocess.PIPE,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage guidance says the skill applies when the user needs output in a language other than Chinese or English, which creates a language-based constraint in the natural-language policy surface. The file does not explain or justify this restriction or offer an explicit user choice around supported languages.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Lines L029-L032 instruct users to avoid specific Chinese phrases, which imposes a language-specific assumption in an otherwise general rewriting guide. Because the file does not state that the skill is only for Chinese resumes or offer locale/user-language selection, this can conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency is specified with a lower-bound only (python-docx>=1.1.2), which makes builds non-reproducible and allows whatever latest compatible release is available at install time. This increases supply-chain risk and can unintentionally introduce vulnerable or breaking versions into the skill environment.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
python-docx>=1.1.2

Unverifiable Dependency: python-docx has 2 known advisory(ies) (CVE-2016-5851 (Improper Restriction of XML External Entity Reference in python-docx); CVE-2016-5851 (python-docx before 0.8.6 allows context-dependent attackers to conduct XML Exter)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The manifest does not pin python-docx to a reviewed version, so it is impossible to verify from this file alone whether deployment will use a version affected by known advisories such as the historical XXE issue. In a CV-generation skill that may process user-supplied document content, unresolved library version uncertainty increases risk if crafted document input reaches vulnerable parsing paths.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill's purpose is generating resumes/CVs and matching outputs, which clearly justifies producing DOCX files. However, this implementation achieves PDF export by discovering and launching an external LibreOffice binary via subprocess, which is a broader execution capability than the manifest suggests and is not necessary for the core document-authoring task itself.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.