Back to skill

Security audit

Jobautopilot Tailor

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed resume-tailoring workflow that reads resume/job-tracker files, writes tailored outputs, and converts them to DOCX without evidence of hidden exfiltration, persistence, or destructive behavior.

Install only if you are comfortable letting the agent read your resume folder and job tracker, fetch job pages, create tailored resume and cover-letter files, and update tracker statuses. Use a dedicated resume folder, review generated documents before sending them, and consider pinning dependencies or running the skill in a restricted environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:18
Finding

Unpinned Third-Party Python Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:18-20 and duplicate package declarations at SKILL.md:41-43
Vulnerability Type: Supply-chain risk caused by unconstrained dependency resolution
Risk Level: Medium

Vulnerable Code

yaml
python_packages:
  - python-docx
  - lxml

The same dependencies are also declared for automatic installation:

yaml
pip:
  - python-docx
  - lxml

Technical Analysis

The Skill declares python-docx and lxml without exact versions or cryptographic integrity hashes. If the hosting framework automatically installs these declarations, each installation resolves whichever compatible releases are available at that time. Consequently, the installed code can differ from the code originally reviewed.

This creates a supply-chain exposure if a dependency release or package-distribution account is compromised. Python package installation and subsequent imports can execute package-controlled code under the identity running the Agent. The risk is especially relevant because this Skill processes resumes, contact information, employment histories, and local output files.

No evidence was found that the currently named packages are malicious. The vulnerability is the absence of reproducible, integrity-verified dependency resolution.

Attack Path

  1. An attacker compromises a declared dependency's distribution account or otherwise causes a malicious release to be served by the configured package index.
  2. The Skill framework installs dependencies from the unconstrained pip declarations.
  3. Dependency installation or import executes attacker-controlled Python code with the Agent process's permissions.
  4. The malicious code reads files available to the Agent, including resume source files, generated documents, tracker data, and environment variables.
  5. Depending on the runtime's network policy, the code may exfiltrate that informa ...[truncated 689 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin each dependency to a reviewed exact version, for example:

    yaml
    python_packages:
      - python-docx==REVIEWED_VERSION
      - lxml==REVIEWED_VERSION
    
  2. Use a lock file or requirements file containing cryptographic hashes and install with hash enforcement, such as pip install --require-hashes.

  3. Keep the top-level and metadata.clawdbot dependency declarations synchronized so they cannot resolve different versions.

  4. Retrieve packages only from an explicitly configured, trusted package index; disable unintended extra indexes to reduce dependency-confusion exposure.

  5. Install dependencies in an isolated virtual environment or container with minimal filesystem and network access.

  6. Run dependency vulnerability and provenance checks before updating pinned versions.

  7. Restrict the Agent process to only the resume, output, template, and tracker paths required for its declared functionality.

Vulnerability Patterns
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code's actual function is a document templating utility: it reads a Markdown file, parses resume sections, and populates a DOCX template with that content while preserving formatting and dynamically cloning/removing template paragraphs. There is no logic for fetching a job description, analyzing keywords, tailoring content to a job, rewriting bullets, generating a cover letter, or interacting with any external skills/services like jobautopilot-search or jobautopilot-submitter. Exporting DOCX is consistent with part of the description, but the primary purpose and major claimed capabilities are absent, so this is a clear description/behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill requires reading from sensitive local paths like $RESUME_DIR and $JOB_SEARCH_TRACKER but does not declare an explicit tool scope such as permissions or allowed-tools. That creates an authorization gap where a caller may not realize the skill can access personal documents and tracker data, increasing the risk of unintended data exposure or over-broad file access.

Content

No source excerpt is available for this finding.

Unbounded Output

Medium
Category
Output Handling
Confidence
80% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · scripts/md_to_docx.py (reported line 263)May include surrounding context.

python
b += 1
    return dict(header=header_idx, bullets=bullets)

# ── main fill logic ───────────────────────────────────────────────────────────

def fill_template(doc: Document, data: dict):
    paras = doc.paragraphs  # live list (reflects structural changes)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs writing markdown/docx files and updating the job tracker, but it does not present a clear user-facing warning that local files will be created and modified. In a workflow involving resumes, contact details, and application trackers, silent modification can cause accidental overwrites, privacy issues, or corruption of important personal records.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.