Back to skill

Security audit

Job Agent for AgentMesh360

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent job-application automation, but its direct remote installer and some automatic update/retry behavior deserve review before installation.

Install only if you trust the publisher and are comfortable with a CLI that uses your resume, API key, browser login sessions, job-site accounts, and paid credits. Prefer reviewing or pinning the installer source before running it, and watch for any update or retry step that proceeds without an explicit prompt.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
Findings (11)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
after the CLI reports insufficient credits with `paid_pass_required=true`.
  After a purchase, ask the user to return here; recheck with `jobagent doctor env`.

A setup turn ends with a clear user handoff (including the return instruction),
a concrete recovery blocker, or verified readiness plus the next user choice.
An install alone does not authorize a new round, paid analysis or delivery.
Preserve existing rounds and confirmations. All later platform actions retain

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

md
`reason=permission_required` and `evidence.host_window_issue` set to the observed
`window_unavailable` or `ax_visual_mismatch`. Relay the CLI prompt asking the user
to bring the original window forward once. Do not infer lockscreen, logout or
missing Computer Use, or cancel, rebind, start a round or clear state to activate
it. Afterward, freshly verify window, profile, official page and bound account;
continue only under current work permissions, without repeating side effects.
If that one user foregrounding does not restore consistent observations, retain

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 187)May include surrounding context.

md
`reason=permission_required` and `evidence.host_window_issue` set to the observed
`window_unavailable` or `ax_visual_mismatch`. Relay the CLI prompt asking the user
to bring the original window forward once. Do not infer lockscreen, logout or
missing Computer Use, or cancel, rebind, start a round or clear state to activate
it. Afterward, freshly verify window, profile, official page and bound account;
continue only under current work permissions, without repeating side effects.
If that one user foregrounding does not restore consistent observations, retain

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 319)May include surrounding context.

md
`reason=permission_required` and `evidence.host_window_issue` set to the observed
`window_unavailable` or `ax_visual_mismatch`. Relay the CLI prompt asking the user
to bring the original window forward once. Do not infer lockscreen, logout or
missing Computer Use, or cancel, rebind, start a round or clear state to activate
it. Afterward, freshly verify window, profile, official page and bound account;
continue only under current work permissions, without repeating side effects.
If that one user foregrounding does not restore consistent observations, retain

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 158)May include surrounding context.

md
the returned current platform, checking each successful result. Only after
`workflow.workflow_complete=true`, run `jobagent round start` and answer its
resume/role/city interactions with the user's choices. Let the CLI archive old
pending state; never delete history or reuse old signatures/candidates as new
results. Do not rerun resume analysis merely for this handoff or promise that
the new round is free; its cloud operations follow their normal billing contract.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The command chains network retrieval and shell execution in one step (| bash), eliminating opportunities for inspection or verification. In the context of a skill that manages credentials, browser sessions, and application workflows, this significantly increases the blast radius of a compromised installer or dependency path.

Content

Scanner excerpt · SKILL.md (reported line 216)May include surrounding context.

macOS/Linux:

bash
curl -fsSL https://raw.githubusercontent.com/jiyangnan/AgentMesh-JobAgent/main/scripts/install.sh | bash

Windows PowerShell:

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
Legacy platform examples below remain compatible command entry points; their
driver-specific recovery descriptions do not override native tasks. The full
Codex instructions are in the public
[Codex skill](https://github.com/jiyangnan/AgentMesh-JobAgent/blob/main/skills/codex-job-agent/SKILL.md).

When the current task offers `app_scoped_window`, a native host without window
IDs can use its actual app reference with fresh window-selection evidence. This

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

md
updated CLI may recover only the original binding from the verified signed
SearchPlan. It must match the account, round, request, Discover, session and
confirmed intent, and pass a fresh check of the same server material. Preflight
does not write the binding; successful recovery continuation checks it again
before restoring it. No signed binding means no binding can be reconstructed.
Never substitute a local profile, current selection or new resume revision.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
83% confidence
Finding

The skill explicitly instructs the agent to continue with next_suggested actions without fresh user confirmation when no user action is pending. In a job-application context, this can cause the agent to advance paid cloud operations or account-scoped workflow transitions that the user may not have explicitly approved in that moment, increasing the risk of overreach.

Content

Scanner excerpt · SKILL.md (reported line 175)May include surrounding context.

md
- Never invent an API Key. Ask the user to create an AgentMesh360 universal Key at `https://agentmesh360.com/app/` and wait. Registration and Key creation are free; cloud capabilities require available credits.
- After configuring the Key, run `jobagent doctor env`. Read `environment_healthy` and `workflow.ready` separately. If `cloud_access.usable=true`, briefly report the active balance source and run the top-level `next_suggested` when no user action is pending. If `requires_user_action=true`, relay the setup prompt and wait; never execute resume or Key placeholders. Never block on `Pass: not purchased`; ask for a purchase only when `paid_pass_required=true` or a real cloud command returns `insufficient_credits`.
- New accounts start with zero cloud credits. Eligible new accounts receive a 3-day welcome pass with 30 shared credits after account verification and the first successful sign-in — no card required, nothing renews automatically. For grandfathered `signup_trial_active`, tell the user: `你的 AgentMesh360 账户仍有此前发放的体验额度:剩余 {credit} credits,有效期至 {expires_at}。无需购买通行证,我现在继续执行下一步。` Then execute `next_suggested` without asking for confirmation.
- `jobagent init` returns `workbench_url=https://agentmesh360.com/workbench/` for the first-run handoff. Existing accounts may receive top-level `announcements` once after a successful account-verified command. For `id=jobagent_workbench_launch_202608`, show a non-blocking information card when the current host interface supports it, or a concise localized message with the URL, then continue the original `next_suggested`. Never ask for acknowledgement, rerun `init`, or repeat the announcement.
- Run Boss直聘 -> 猎聘 -> 智联招聘 -> 51Job as complete vertical chains. Never pre-login future platforms; complete the current platform's `login -> discover -> review -> delivery preview -> delivery confirmation -> send -> audit` chain and complete its audit before logging in to the next platform. Never operate their shared browser concurren
...[truncated 24 chars]

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
87% confidence
Finding

The skill directs the agent to perform managed updates and immediately run retry/recovery commands without asking the user in some cases. Although framed as safe recovery, this authorizes autonomous execution of state-changing commands and can normalize silent continuation through sensitive account, browser, and billing-related workflows.

Content

Scanner excerpt · SKILL.md (reported line 202)May include surrounding context.

md
- After an existing installation updates, run `jobagent upgrade-check` and resolve its `next_suggested` action before opening a platform. Never delete `~/.jobagent` or the Job Agent Chrome profile as a general fix; preserve credentials, login cookies, profiles, audits and preferences.
- Forward `client_update_detected -> client_update_started -> client_update_completed -> client_command_resumed` once in the user's language. Do not ask permission for a managed signed update and do not stop after success; continue the original command. Stop only on `client_update_failed`, report its `message`, and follow `next_suggested`. Older clients may first emit only the compatibility completion/resume pair.
- For `client_update_failed` with `error_code=release_artifact_hash_mismatch`, run the returned official-installer recovery command once and repeat the original command. It preserves Job Agent state and browser sessions; never disable the signature/tag/commit/archive checks or delete the managed profile.
- When a cloud command returns `retryable=true` and `request_preserved=true`, do not ask the user to retry, re-login or recollect jobs. Run the exact `next_suggested` command immediately. A failed start reuses its persisted `request_id` and has `billing_status=not_charged`; a failed decision reuses its `discover_id` and preserved candidates without an additional charge. If a valid signed SearchPlan expires during a preserved request, the CLI renews that same `request_id` and `discover_id` automatically with zero renewal charge; never create a replacement round or recollect jobs. Signature, account or context mismatches remain hard stops.
- Treat every signed SearchPlan `page_limit` as an upper bound. The CLI stops a query after explicit no-results or a verified final page, then continues any remaining signed queries. On `no_candidates` with `search_exhausted=true`, show the empty outcome and wait for the user's explicit platform-skip decision; never repeat the same Discover c
...[truncated 25 chars]

External Script Fetching

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs users to install by piping a remote GitHub script directly into bash, which executes unreviewed code fetched at runtime. If the repository, branch, CDN path, or transport context is compromised, this becomes an immediate remote code execution path on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 216)May include surrounding context.

macOS/Linux:

bash
curl -fsSL https://raw.githubusercontent.com/jiyangnan/AgentMesh-JobAgent/main/scripts/install.sh | bash

Windows PowerShell:

Static analysis

No suspicious patterns detected.