Back to skill

Security audit

Harvard Style CV Creator

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent resume and cover-letter generator, but it tells the agent to install an unpinned npm package globally, which can persistently change the environment.

Review this skill before installing in shared or sensitive environments. It should be changed to use a pinned, project-local dependency or require explicit approval before any global npm installation; generated resumes and cover letters may contain sensitive personal information, so review output paths and final documents carefully.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:166
Finding

Unpinned Global npm Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 166–172
Vulnerability Type: Unsafe third-party dependency installation
Risk Level: Medium

Vulnerable Code

markdown
### Dependency: `docx` npm package

Check if already installed, install if not:
```bash
npm list -g docx 2>/dev/null | grep docx || npm install -g docx

This skill requires docx v9+. No other runtime dependencies beyond Node.js.

text

The same unsafe installation behavior is also declared in `SKILL.md`, line 13, and documented in `README.md`, lines 47–52.

### Technical Analysis

The Skill instructs the Agent to install the latest package named `docx` globally without pinning an exact audited version or verifying package integrity. The command therefore trusts whatever package release the configured npm registry resolves at execution time.

This creates a supply-chain risk because a compromised registry account, malicious future release, registry substitution, or altered npm configuration could cause unreviewed code to be installed. npm packages may also contain lifecycle scripts that execute during installation with the permissions of the Agent process.

The dependency check does not enforce the stated requirement for `docx` version 9 or later. `grep docx` merely checks for matching output, so an already installed incompatible version may satisfy the condition and suppress installation.

Global installation unnecessarily modifies the shared Node.js environment. The installed package can consequently influence this Skill and other workloads that use the same global package location.

### Attack Path

1. An attacker compromises the relevant npm package release channel or controls the npm registry configured in the execution environment.
2. The `docx` package is absent when the Skill is invoked.
3. The Agent executes:
   ```bash
   npm install -g docx
  1. npm retrieves an unconstrained package version from the configured registry.
  2. Malicious package code or li ...[truncated 949 chars]
Remediation
View remediation

Remediation Suggestions

  1. Define the dependency in a project-local package.json using an exact, reviewed version rather than a floating range:

    json
    {
      "dependencies": {
        "docx": "9.x.y"
      }
    }
    

    Replace 9.x.y with the exact approved release.

  2. Commit a lockfile and use deterministic local installation:

    bash
    npm ci --ignore-scripts
    
  3. Review whether the selected package requires lifecycle scripts. Keep --ignore-scripts enabled unless a specific audited script is essential.

  4. Import the project-local dependency rather than modifying or relying on the global Node.js environment.

  5. Verify the installed version explicitly at runtime and fail closed when it is outside the supported range.

  6. Use the official npm registry through a trusted configuration, retain lockfile integrity hashes, and incorporate dependency vulnerability and provenance checks into release review.

  7. Remove the global installation instructions from SKILL.md, its compatibility metadata, and README.md so the unsafe path is not invoked through an alternate instruction.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README lists example triggers such as "Write my resume," "Help me with my CV," and "Update my resume," which are common everyday requests and could match broad conversational intent. The file does not provide narrowing conditions, exclusion examples, or clear constraints on when the skill should activate versus when it should not.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest says to use this skill when a user asks to create, write, build, draft, or improve a resume, CV, or cover letter, and also when the user shares their background and asks for help getting it into document form. These conditions are broad natural-language triggers without exclusion conditions or scope limits, which can cause unintended invocation for general career-advice conversations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to install a global npm package and write files to fixed filesystem locations without an explicit consent or warning boundary. That can cause unapproved system modification, persistent environment changes, and filesystem side effects, especially in shared or sensitive execution environments.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

At L072 the document says to read references/harvard-rules.md before generating any document, while L088 states the skill is self-contained and that no external skill files need to be read. These statements directly conflict about whether external file access is required.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The document is written as a universal ruleset tied to a specific institution ('Harvard Office of Career Services') and presents its guidance as mandatory without stating that this style is optional or only for users who want Harvard-style conventions. That can create a natural-language policy concern if the skill applies these norms broadly without user opt-in to this institutional style.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.