Back to skill

Security audit

Interview Analysis

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only interview analysis skill whose behavior is mostly disclosed and purpose-aligned, but users should handle saved candidate evaluations carefully.

Install only from a trusted source, prefer pinned installer versions, and avoid running npx installers in environments with unnecessary credentials. Treat transcripts and generated cards as confidential hiring records: store them outside public repositories or synced folders unless access controls, retention, and deletion practices are clear.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:65
Finding

Unpinned Packages Executed Through npx

Content
View full analysis

Vulnerability Details

File Location: README.md:65-75
Vulnerability Type: Supply-chain risk from unpinned executable dependencies
Risk Level: Medium

Vulnerable Code:

markdown
## Install

**ClawHub (OpenClaw)**:
```bash
npx clawhub@latest install interview-analysis

Other (e.g. skills.sh):

bash
npx skills add mikonos/interview-analysis
text

### Technical Analysis

The documented installation commands cause `npx` to retrieve and execute third-party packages from a package registry. The first command explicitly selects `clawhub@latest`, while the second invokes the unversioned `skills` package. Neither command pins an audited version or verifies a cryptographic signature or integrity digest.

Consequently, the code executed when a user follows the documentation may differ from the version originally reviewed. A compromised package publisher, registry account, transitive dependency, or subsequently malicious release could introduce arbitrary executable behavior. This issue requires a user or automation system to run one of the documented installation commands; the repository itself does not contain an embedded malicious script.

### Attack Path

1. An attacker compromises the publisher account, package distribution channel, or dependency chain for `clawhub` or `skills`.
2. The attacker publishes a malicious version under the package name used by the documentation.
3. A user follows `README.md` and executes the applicable unpinned `npx` command.
4. `npx` retrieves the current registry package rather than a fixed, previously audited artifact.
5. The package CLI or applicable lifecycle behavior executes with the privileges and environment of the invoking user.
6. The malicious package can access resources available to that user, subject to operating-system and runtime restrictions.

### Impact Assessment

Successful exploitation could permit arbitrary code execution with the i
...[truncated 462 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin each installer package to a specific reviewed version, for example npx clawhub@X.Y.Z, rather than using @latest or an unversioned package.
  2. Use the package manager's option to reject implicit installation where available, ensuring unexpected missing packages are not fetched silently.
  3. Publish and verify cryptographic signatures or integrity digests for installation artifacts.
  4. Document the expected package publisher, registry, version, and checksum so users can validate provenance before execution.
  5. Review and pin transitive dependencies through lockfiles in any maintained installer implementation.
  6. Run installation under a non-privileged account in a restricted environment, without unnecessary credentials or sensitive environment variables.
  7. Establish a release process that performs dependency scanning and reproducible verification before updating the documented installer version.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Hidden Instructions

High
Category
Prompt Injection
Confidence
91% confidence
Finding

The HTML comment contains hidden instructions directed at an AI system, including guidance to dynamically choose expert models and evaluation dimensions by referencing another file. Hidden prompt-layer instructions are dangerous because they can silently influence agent behavior outside the visible user-facing template, reducing transparency and creating an avenue for prompt injection or unintended control flow if downstream systems ingest template comments.

Content

Scanner excerpt · templates/insight_template.md (reported line 12)May include surrounding context.

md
## Part 1: {Core Competency} Deep Dive ({Domain} Deep Dive)

<!-- 
Guidance for AI:
Dynamically design {Expert_Model} and evaluation dimensions:

Hidden Instructions

High
Category
Prompt Injection
Confidence
87% confidence
Finding

The HTML comment contains hidden instructions directed at the AI, including dynamic persona-selection logic and a reference to external skill content. Hidden model-facing instructions are risky because they can silently steer outputs in ways a human reviewer may not notice, and can create prompt injection surfaces when the model gives privileged weight to commented guidance over visible user intent.

Content

Scanner excerpt · templates/profile_template.md (reported line 6)May include surrounding context.

md
> [!NOTE]
> **Analysis Perspective**: Based on {Expert_Persona_1} and {Expert_Persona_2}'s hiring philosophy.
> **Core Conclusion**: A **{core determination: e.g., strong executor / disguised strategist}**, but **{qualifying assessment: e.g., lacks foundational innovation / possesses high potential}**.
<!-- 
Guidance for AI:
Dynamically select {Expert_Persona_X} based on candidate's role:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README states that analysis cards are written to people/{candidate_name}/analysis/ but does not warn that interview transcripts and derived evaluations may contain highly sensitive personal data. In a hiring context, this increases the chance of storing PII and confidential assessments in plaintext, sync folders, or repositories without appropriate access controls.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The README instructs users to run npx clawhub@latest install interview-analysis, which pulls and executes the latest package version at install time. This creates a supply-chain risk because a compromised or malicious upstream release could be executed without review, and the interview-analysis context does not reduce that risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
85% confidence
Finding

The README tells users to run npx skills add mikonos/interview-analysis without pinning a package version or immutable reference. If the referenced package or resolution path is changed upstream, users may execute unexpected code during installation, making this a real supply-chain exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description is broad enough to match many ordinary requests about interviews, analysis, or professional evaluation, which can cause the skill to activate when the user did not explicitly intend to invoke it. In this context, unintended activation is more dangerous because the skill also instructs saving candidate analysis artifacts to persistent paths, increasing the chance of processing and persisting sensitive interview data without clear user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill directs the agent to write candidate-specific analysis files under persistent paths without warning the user that interview content and evaluation notes may be stored. Because interview transcripts and assessments often contain sensitive personal and employment-related information, silent persistence creates privacy, retention, and unauthorized disclosure risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comment instructs the AI to choose dimensions that 'best expose imposters,' which is a natural-language policy concern because it frames candidates in a pejorative, presumptive way. This kind of wording can encourage unfair or biased evaluation behavior in downstream use.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · templates/profile_template.md (reported line 20)May include surrounding context.

md
- Whose framework best validates the authenticity of core competencies?
- If the role lacks obvious "masters," choose domain practitioners or first-principles thinkers

**Reference SKILL.md Section 1's expert mapping table**, but not limited to it.
-->

## 1. Resume Verification

Static analysis

No suspicious patterns detected.