Back to skill

Security audit

HR简历分析评分报告

Security checks for vulnerabilities and agentic risk

Overview

This resume-scoring skill is not clearly malicious, but it needs review because it handles sensitive candidate data and includes unsafe guidance around local files, broad file selection, administrator execution, and third-party document upload.

Review before installing. Use it only for authorized HR workflows, process only explicit files in a dedicated directory, avoid external compression services for resumes, do not run it as administrator, pin dependencies in a virtual environment, and define deletion/redaction rules for generated reports and temporary files. Treat subjective scoring and risk labels as prompts for human review, not automated hiring decisions.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:370
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Execution Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:370-378
Vulnerability Type: Unpinned runtime dependencies
Risk Level: Medium

Vulnerable Code

bash
pip install PyMuPDF
pip install pdfplumber
pip install python-docx
pip install pandas openpyxl

Technical Analysis

The installation instructions do not pin package versions, verify package hashes, use a reviewed lockfile, or require an isolated environment. Consequently, the exact code installed and executed can change after the Skill has been reviewed.

Python package installation may execute package-controlled build or installation logic. If a dependency release or its distribution channel is compromised, following these instructions could execute attacker-controlled code. The finding does not establish that any listed package is currently malicious; it identifies an unsafe dependency-management practice that exposes users to future upstream or supply-chain compromise.

Attack Path

  1. An attacker compromises an upstream package account, distribution artifact, or dependency release.
  2. A user follows the Skill instructions at a later date.
  3. pip resolves the mutable package name to the compromised release.
  4. Package-controlled installation logic executes under the user's account.
  5. The installed package can execute again when the resume-processing workflow imports it.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user running pip or the resume processor. Accessible data may include candidate resumes, generated reports, files available to the user, environment variables, and application credentials. If combined with the separate recommendation to run as administrator, the potential scope could expand to system-level modification.

Remediation
View remediation

Remediation Suggestions

  • Pin every direct and transitive dependency to a reviewed version.
  • Publish a lockfile or requirements file containing cryptographic hashes.
  • Install with hash verification, such as pip install --require-hashes -r requirements.txt.
  • Install dependencies in a dedicated, least-privileged virtual environment.
  • Use an approved package index and disable unexpected fallback indexes.
  • Perform dependency vulnerability and provenance scanning before releases.
  • Document a controlled update process rather than resolving the newest package versions at installation time.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:512
Finding

Resume Processing Instructions Recommend Unnecessary Administrator Privileges

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:512
Vulnerability Type: Unnecessary privilege escalation guidance
Risk Level: High

Vulnerable Instruction

text
Run as administrator

Technical Analysis

Parsing user-owned resumes does not ordinarily require administrator privileges. Recommending elevation in response to a file-access error violates least-privilege principles and magnifies the consequences of vulnerabilities in document parsers, imported dependencies, or crafted resume files.

Resume processing operates on untrusted documents. Elevating the entire workflow means any code execution obtained through a compromised dependency or parser vulnerability would inherit administrator rights rather than remaining confined to a standard user account.

Attack Path

  1. A user encounters a file-access error while following the workflow.
  2. The Skill instructs the user to rerun the operation as administrator.
  3. The elevated process loads third-party parsing libraries and processes an untrusted resume.
  4. A malicious dependency or exploitable document triggers code execution.
  5. The resulting payload executes with administrator privileges.

Impact Assessment

Successful exploitation could permit system-wide file modification, security-setting changes, access to other users' data, installation of persistent components, and compromise of all candidate records available to the host. The instruction does not itself bypass operating-system authorization, but it induces the user to grant privileges beyond those legitimately needed by the task.

Remediation
View remediation

Remediation Suggestions

  • Remove the recommendation to run the resume processor as administrator.
  • Require execution under a dedicated, non-privileged account.
  • Diagnose access failures by checking ownership and access-control settings for the specific input and output paths.
  • Copy authorized input files into a user-owned, access-restricted workspace rather than elevating the process.
  • Run document parsers in a sandbox or container with read-only inputs, restricted network access, and a narrowly scoped output directory.
  • Explicitly warn users not to elevate the parser or dependency installer.

other

Warning
Location
SKILL.md:428
Finding

External PDF Compression Recommendation May Disclose Candidate Personal Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:428
Vulnerability Type: Sensitive data disclosure to a third-party service
Risk Level: Medium

Vulnerable Instruction

text
If the file is a PDF, try compression: https://smallpdf.com/compress-pdf

Technical Analysis

Resumes commonly contain personally identifiable information, including names, telephone numbers, email addresses, education history, employment records, and potentially home addresses. The Skill directs users to an external document-processing service without requiring candidate consent, organizational authorization, redaction, a privacy review, or verification of retention and data-residency terms.

Following the recommendation requires transmitting the complete resume outside the local processing boundary. This creates a direct disclosure path even though the project itself does not contain automated upload code.

Attack Path

  1. A resume exceeds the documented file-size limit.
  2. The user follows the external compression recommendation.
  3. The user uploads the unredacted resume to the third-party service.
  4. The service receives and processes candidate personal information.
  5. The data may become subject to third-party storage, logging, retention, subprocessors, or a different legal jurisdiction.

Impact Assessment

The exposed scope may include all personal and professional information contained in each uploaded resume. Potential consequences include privacy-policy violations, contractual breaches, regulatory exposure, unauthorized profiling, and loss of candidate confidentiality. This finding does not assert misconduct by the named service; the risk arises from directing sensitive documents to an external processor without governance controls.

Remediation
View remediation

Remediation Suggestions

  • Replace the external upload recommendation with an approved offline PDF-compression method.
  • If external processing is unavoidable, require explicit organizational approval and a documented data-processing agreement.
  • Obtain appropriate consent and disclose the external processor before upload.
  • Remove or redact unnecessary personal information before transmission.
  • Verify encryption, retention, deletion, subprocessor, and data-residency policies.
  • Provide a configurable allowlist of organization-approved document services rather than hardcoding a public service.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:666
Finding

Resume Contents Are Stored in a Predictable Plaintext Temporary File

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:666-670
Vulnerability Type: Insecure temporary-file handling
Risk Level: Medium

Vulnerable Code

python
with open("temp_resume.txt", "w", encoding="utf-8") as f:
    f.write(user_pasted_text)

resume = ResumeParser.parse_file("temp_resume.txt")

Technical Analysis

The example writes sensitive resume contents to the fixed relative path temp_resume.txt. It does not securely create the file, restrict permissions, prevent collisions, validate whether the path already exists, or delete the file after processing.

A predictable name permits accidental overwriting and creates a stable location that another local process or user may monitor. Depending on the working-directory permissions and platform defaults, the file may be readable by unintended principals. Because no cleanup occurs, candidate data can persist in the workspace, backups, development artifacts, or later collection operations.

Attack Path

  1. A user pastes sensitive resume text into the workflow.
  2. The Skill writes the complete content to the predictable temp_resume.txt path.
  3. Another local principal, process, backup agent, or workspace collector reads the file.
  4. The parser completes without deleting the plaintext artifact.
  5. Candidate information remains available after its intended processing lifecycle.

A separate collision scenario is also possible: an existing file at that path is silently truncated by write mode, resulting in data loss.

Impact Assessment

Exposure is limited to the resume content written to the temporary file but may include names, contact details, education, employment history, and other candidate information. Any local principal with access to the working directory may potentially retrieve it. Repeated runs overwrite the same location, and the absence of cleanup extends the disclosure window beyond the active operation.

Remediation
View remediation

Remediation Suggestions

  • Prefer parsing the supplied text directly in memory without creating a file.
  • If a file is mandatory, use a secure temporary-file API that creates a unique file atomically.
  • Create the file with permissions limited to the current process or user.
  • Place temporary data in a private, access-restricted directory.
  • Delete the file in a finally block so cleanup occurs after both successful and failed parsing.
  • Avoid persistent logging, backups, or report attachments containing raw resume text.
  • Define and enforce a retention policy for all candidate data.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is designed to ingest resumes containing PII such as names, phone numbers, email addresses, education, and employment history, yet it provides no privacy notice or data-handling constraints. In an HR context, silent processing of candidate personal data raises significant confidentiality and compliance risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow generates Excel/JSON/Markdown reports containing candidate information and scores without warning users that sensitive data will be written to persistent files. Persistent exports materially increase exposure through local storage, sharing, backups, and accidental transmission.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions explicitly save pasted resume content to a local temporary file without disclosing that sensitive personal data will be stored on disk. Even temporary local files can persist, be indexed, included in backups, or be accessed by other processes/users, creating avoidable privacy exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description says the skill triggers whenever the user needs to screen resumes, evaluate candidates, score resumes, analyze matching, or generate reports, but it does not clearly constrain activation boundaries or provide exclusion cases. Several phrases are broad enough to overlap with ordinary HR conversation, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description and the rest of the file are entirely in Chinese, and the skill presents all triggers, prompts, and outputs in that language with no indication that users may choose another language. This can be a language/locale policy issue when a skill implicitly forces one language without opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Phrases like “帮我筛选这批简历”, “简历打分”, “评估这份简历”, and “给这个候选人打分” are natural requests that could appear in casual discussion, but the document does not specify what qualifies as invocation versus ordinary advice. The section also lacks negative examples or contextual limits to reduce accidental activation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill expands from resume scoring into personality, leadership potential, and team-fit inference, which are sensitive and subjective assessments not clearly necessary for the stated purpose. This increases privacy and fairness risk because the agent may derive consequential attributes from resume text without explicit user consent, validation, or guardrails.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The authenticity and background-risk section adds quasi-investigative screening beyond basic resume parsing/scoring, encouraging the system to infer deception or credibility risk from limited text signals. Such outputs can cause harmful false positives and process sensitive candidate data in ways users may not expect from a resume-scoring tool.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The conversation guide instructs the agent to glob the working directory and select files automatically, which can cause the skill to process unintended local files beyond those the user explicitly provided. In a workspace containing other resumes or sensitive documents, this broadens access scope and can leak or mix personal data across sessions/tasks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

Earlier in the file, supported formats are described as PDF, .docx, .txt, and .md, and the limitations section explicitly says old .doc is not supported. The error-handling text here instead lists '.doc' as supported, which creates a clear description-level mismatch within the skill documentation about actual behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.