Back to skill

Security audit

Interview Buddy

Security checks for vulnerabilities and agentic risk

Overview

This interview coaching skill is purpose-aligned but should be reviewed because it mandates billable third-party API calls and sends email, OTP, and interview content through shell commands without clear consent or safer input handling.

Install only if you are comfortable sending your email, OTP flow, role/company details, interview answers, and other interview-prep content to ToolWeb and potentially consuming paid API quota. Avoid sharing confidential employer, project, customer, or proprietary information, and prefer an implementation that asks for consent before each external session and safely serializes request bodies instead of interpolating user text into shell commands.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:43
Finding

Mandatory Billable Third-Party Processing Overrides Agent Autonomy

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:69
Finding

Sensitive Credentials and Authentication Data Exposed Through Command-Line Arguments

Content
View full analysis
"}' ``` Endpoint path: `/auth/send-otp` **Step 2: Verify OTP** ```bash curl -s -X POST "https://portal.toolweb.in/apis/tools/interview-buddy" \ -H "Content-Type: application/json" \ -H "X-API-Key: $TOOLWEB_API_KEY" \ -d '{"email": "", "otp": ""}' ``` Endpoint path: `/auth/verify-otp` ``` ### Technical Analysis The documented authentication flow places the API key in a command-line header argument and places the email address and one-time password in the `curl` data argument. Although TLS protects these values while they are transmitted over the network, it does not protect them from local exposure before transmission. Depending on the operating system, runtime, and agent implementation, command-line arguments may be visible through: - Process inspection facilities. - Process accounting or endpoint telemetry. - Debug logs that record executed tool arguments. - Agent execution traces. - Error reports or command auditing systems. An OTP is short-lived, but exposure during its validity window could permit unauthorized session creation. Exposure of `TOOLWEB_API_KEY` could permit unauthorized API usage until the key is revoked or expires. The use of `curl -s` also suppresses progress and some diagnostics without establishing secure secret handling. It does not mitigate command-line credential exposure. ### Attack Path 1. The agent requests or receiv ...[truncated 1213 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:90
Finding

Shell Command Injection Risk from Unsafe Interpolation of Interview Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to always call a third-party API and transmit user email, interview prompts, and ongoing responses, but it does not provide a clear upfront warning or require explicit user consent for that external transfer. Because interview practice may include sensitive personal, employment, or proprietary information, silent transmission to an external service creates a meaningful privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file includes very broad activation language such as 'Use when preparing for job interviews' and 'User needs interview preparation help,' which overlaps with common everyday requests. It does not provide narrowing constraints or negative examples to distinguish when this skill should activate versus when a general assistant response would be more appropriate.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow routes OTP-related data and then continuously forwards user interview answers to a third-party service over the course of the conversation. This creates sustained exfiltration risk, especially because users may reveal resumes, work history, company details, confidential project information, or other sensitive personal data while the skill encourages continued transmission.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This curl command sends the user's email address to an external endpoint as part of OTP authentication. External transmission is expected for this feature, but in the current skill it occurs within a pattern of mandatory third-party use without prominent disclosure, making the data transfer security-relevant rather than harmless.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

Step 1: Send OTP

bash
curl -s -X POST "https://portal.toolweb.in/apis/tools/interview-buddy" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $TOOLWEB_API_KEY" \
  -d '{"email": "<user_email>"}'

Static analysis

No suspicious patterns detected.