Back to skill

Security audit

Resume Create

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent resume generator, but its HTML template can execute unsafe content from resume fields when opened for PDF export.

Review this skill before installing if you may process resumes from untrusted sources. Generated resume files can contain sensitive personal data and are retained locally, and the current template should be fixed to escape text, validate links, and avoid innerHTML before it is used on attacker-controlled resumes.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
assets/template.html:134
Finding

Unsanitized Resume Data Enables HTML and JavaScript Injection

Content
View full analysis
{ const sep = i < data.info.length - 1 ? '|' : ''; return `${item}${sep}`; }).join(''); return `

${data.name}

${data.tagline}
${infoHtml}
`; } ``` ```javascript function renderProjectList(projList) { const items = projList.map(p => { const techHtml = p.tech.map(t => `${t}`).join(''); const linkHtml = p.link ? `${p.link}` : ''; const listHtml = p.items.length > 0 ? `
    ${p.items.map(i => `
  • ${i}
  • `).join('')}
` : ''; const nameHtml = p.name ? `${p.name}${p.alias ? '' + p.alias : ''}` : (p.alias || ''); return `
${nameHtml} ${p.date}
${linkHtml}
${p.desc} ${listHtml}
${techHtml}
`; }).join(''); return `
${renderSectionTitle('项目经验')} ${items}
`; } ``` ```javascript function render() { const app = document.getElementById('app'); const d = resumeData; const sections = []; if (d.header) sections.push(renderHeader(d.header)); if (d.summary) sections.push(renderSummary(d.summary)); if (d.workExperience && d.workE ...[truncated 3605 chars]
Remediation
View remediation
... ``` - Before embedding JSON in HTML, escape at least `<` as `\u003c` so that user data cannot form ``. - Read and parse it using: ```javascript const resumeData = JSON.parse( document.getElementById('resume-data').textContent ); ``` - Alternatively, load data from a separately generated JSON file under an appropriately restrictive local policy. 3. **Validate the complete input schema** - Require the expected object, array, and string types. - Enforce reasonable length limits and reject unexpected properties. - Normalize imported resume content to plain text before rendering. - Do not preserve HTML from PDF, DOCX, HTML, Markdown, or text imports. 4. **Validate project links** - Parse links with the `URL` API. - Allow only an explicit set of schemes, preferably `https:` and optionally `http:`. - Reject `javascript:`, `data:`, `file:`, and other unneeded schemes. - Set link text with `textContent` and the validated URL through the DOM `href` property. - When using `target="_blank"`, also set `rel="noopener noreferrer"`. 5. **Apply defense-in-depth browser controls** - Add a restrictive Content Security Policy that blocks inline scripts and event handlers. - Permit network connections only when strictly required; otherwise use `connect-src 'none'`. - Avoid granting the PDF-rendering browser access to privileged automation bridges or unrelated local files ...[truncated 386 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
3. **生成 HTML** — 读取 `assets/template.html`,将 `__RESUME_DATA__` 替换为实际数据 JSON,保存为 `{名字}-{职位}.html`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill directs the agent to perform web searches based on the user's target job information without any privacy notice or consent step. Even if the query is limited to a job title, it still transmits user-derived intent data to external search providers, and in practice agents may include more contextual details than necessary, exposing sensitive career interests or personal context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly saves generated HTML and PDF files in the workspace and instructs the agent to retain both files, but it does not require notifying the user beforehand about local file creation, storage location, or retention. Because resumes contain sensitive personal data such as name, phone number, email, city, education, and employment history, silent persistence increases privacy risk through unintended retention or later access by other processes or users of the environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTML document hard-codes lang="zh-CN", which imposes a specific language/locale on all rendered output. The file does not provide any user opt-in, locale selection mechanism, or documented region-specific justification for this constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.