T09 · Insecure Skill Coding Practices
- Location
examples/test-engineer-resume-score-chat.md:4- Finding
Plaintext Candidate Employment Data Included in Example Output
- Content
View full analysis
Vulnerability Details
File Location:
examples/test-engineer-resume-score-chat.md, lines 4–8, 28–51, and 78
Vulnerability Type: Plaintext sensitive personal data exposure
Risk Level: MediumVulnerable Content
markdown - 姓名:管银敬 - 年限:7.5 - 学历:本科 - 当前岗位:软件测试工程师 - 当前公司:长久集团The same file also lists the candidate's detailed technical skills and industry history at lines 28–51:
markdown - AI应用测试 - LLM应用测试 - 接口测试 - 前后端测试 - Postman - JMeter - SQL - Python - Java - pytest - Selenium - Charles - Fiddler - Linux - kubectl - Jira - Tapd ### 行业标签 - AI大模型 - 企业级SaaS - 金融监管 - 汽车行业 - 汽车金融 - 人资管理Line 78 contains a consolidated employment profile:
markdown - 简历摘录:拥有 7 年 + 软件测试全流程实战经验,负责 AI 话术挖掘、汽车金融监管平台、HR 数字化管理平台和车险系统测试,熟悉 Postman、JMeter、SQL、Linux、Charles、Fiddler、pytest 和 Selenium。Technical Analysis
The example file stores a named candidate's employment attributes, employer, experience, technical skills, industry history, and project domains in plaintext. These fields collectively form candidate-linked personal and professional information.
The data is inconsistent with the repository's sanitized source fixture in
examples/test-engineer-resume.txt, which uses fictionalized values such as李昊,XX在线教育有限公司, andXX大学. This inconsistency indicates that the chat example was not generated exclusively from the sanitized fixture and may contain resume-derived information that was not adequately anonymized.Because the information is committed directly to the project, it is exposed to every package recipient, repository clone, archive, cache, and downstream mirror. No code execution is required to access it.
Attack Path
- An attacker downloads, clones, indexes, or receives the Skill package.
- The attacker opens
examples/test-engineer-resume-score-chat.md. - The attacker extracts the candidate's name, employer, experience, skills, industries, and project history.
- The attacker correlates these attributes with pu ...[truncated 758 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the current candidate-linked example from repository history where operationally feasible, not merely from the latest revision.
- Replace the name, employer, project history, industries, and other identifying attributes with explicitly fictional values.
- Regenerate the chat example solely from the sanitized fixture in
examples/test-engineer-resume.txtto ensure consistency. - Review all examples, generated artifacts, release archives, tags, mirrors, and package registries for copies of the same information.
- Add automated pre-commit and CI checks for personal data and secrets. Flag likely names, email addresses, phone numbers, employers, identification numbers, addresses, and resume-style profiles.
- Require documented consent and defined retention controls before committing any real resume-derived content.
- Establish fixture-generation rules that permit only synthetic candidate data in public or distributable Skill packages.
- Add a release checklist requiring manual privacy review of examples and generated outputs.
