Back to skill

Security audit

HRClaw JD & Resume Scorecard

Security checks for vulnerabilities and agentic risk

Overview

The skill does the advertised hiring-scorecard work, but it handles resume personal data with weak safeguards and includes a real-looking candidate profile in a packaged example.

Review before installing. This skill appears non-malicious, but only use it with resumes you are authorized to process, avoid implicit handling of attached PDFs, and redact names, employers, and resume excerpts before sharing results in team chat. The publisher should replace the candidate-like packaged example with fully synthetic data and add clear privacy handling instructions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
examples/test-engineer-resume-score-chat.md:4
Finding

Plaintext Candidate Employment Data Included in Example Output

Content
View full analysis

Vulnerability Details

File Location: examples/test-engineer-resume-score-chat.md, lines 4–8, 28–51, and 78
Vulnerability Type: Plaintext sensitive personal data exposure
Risk Level: Medium

Vulnerable Content

markdown
- 姓名:管银敬
- 年限:7.5
- 学历:本科
- 当前岗位:软件测试工程师
- 当前公司:长久集团

The same file also lists the candidate's detailed technical skills and industry history at lines 28–51:

markdown
- AI应用测试
- LLM应用测试
- 接口测试
- 前后端测试
- Postman
- JMeter
- SQL
- Python
- Java
- pytest
- Selenium
- Charles
- Fiddler
- Linux
- kubectl
- Jira
- Tapd

### 行业标签
- AI大模型
- 企业级SaaS
- 金融监管
- 汽车行业
- 汽车金融
- 人资管理

Line 78 contains a consolidated employment profile:

markdown
- 简历摘录:拥有 7 年 + 软件测试全流程实战经验,负责 AI 话术挖掘、汽车金融监管平台、HR 数字化管理平台和车险系统测试,熟悉 Postman、JMeter、SQL、Linux、Charles、Fiddler、pytest 和 Selenium。

Technical Analysis

The example file stores a named candidate's employment attributes, employer, experience, technical skills, industry history, and project domains in plaintext. These fields collectively form candidate-linked personal and professional information.

The data is inconsistent with the repository's sanitized source fixture in examples/test-engineer-resume.txt, which uses fictionalized values such as 李昊, XX在线教育有限公司, and XX大学. This inconsistency indicates that the chat example was not generated exclusively from the sanitized fixture and may contain resume-derived information that was not adequately anonymized.

Because the information is committed directly to the project, it is exposed to every package recipient, repository clone, archive, cache, and downstream mirror. No code execution is required to access it.

Attack Path

  1. An attacker downloads, clones, indexes, or receives the Skill package.
  2. The attacker opens examples/test-engineer-resume-score-chat.md.
  3. The attacker extracts the candidate's name, employer, experience, skills, industries, and project history.
  4. The attacker correlates these attributes with pu ...[truncated 758 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the current candidate-linked example from repository history where operationally feasible, not merely from the latest revision.
  2. Replace the name, employer, project history, industries, and other identifying attributes with explicitly fictional values.
  3. Regenerate the chat example solely from the sanitized fixture in examples/test-engineer-resume.txt to ensure consistency.
  4. Review all examples, generated artifacts, release archives, tags, mirrors, and package registries for copies of the same information.
  5. Add automated pre-commit and CI checks for personal data and secrets. Flag likely names, email addresses, phone numbers, employers, identification numbers, addresses, and resume-style profiles.
  6. Require documented consent and defined retention controls before committing any real resume-derived content.
  7. Establish fixture-generation rules that permit only synthetic candidate data in public or distributable Skill packages.
  8. Add a release checklist requiring manual privacy review of examples and generated outputs.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a hiring-assistant skill that ingests job descriptions and PDF resumes and outputs structured hiring recommendations and interview content. The supplied code does none of that. It contains only presentation logic for generating animated promotional/demo GIFs from hardcoded text using Pillow, plus reading a local logo image and writing output GIF files. There is no input handling for JDs or resumes, no PDF parsing, no decision/scoring engine beyond static demo copy, and no Feishu/DingTalk integration or formatting. This is a clear description-behavior mismatch with a materially different primary purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly processes resumes, extracts candidate profile fields, and structures hiring decisions, but it includes no privacy notice, data-minimization guidance, retention limits, or warning about handling sensitive personal data. Because resumes commonly contain PII and sometimes sensitive attributes, this omission can lead users to expose personal data without adequate safeguards, increasing privacy, compliance, and misuse risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The default prompt is broad enough to implicitly trigger on common hiring-related requests such as turning a JD into a scorecard or scoring a resume, which can cause the skill to activate without clear user intent. Because the skill also directs processing of attached PDF resumes, unintended invocation could lead to unnecessary handling of sensitive applicant data and unexpected actions in ordinary conversations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON skill content is entirely written in Chinese, including the summary, interview questions, assumptions, and next steps, with no indication that language choice is optional or limited to a China-specific workflow. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This JSON skill artifact contains user-facing summary, interview questions, red flags, assumptions, and next steps entirely in Chinese. Under the stated policy, forcing a specific language without user opt-in or a documented region-specific justification is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This manifest-like JSON is entirely scoped to a Chinese-language role definition and interview flow, with no indication that language is selectable or that the skill is intentionally limited to a Chinese-speaking context. The policy specifically calls for flagging language or locale constraints when they are imposed without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains only Chinese headings and content, which imposes a specific language on the user without any visible opt-in or justification. Under the policy, forcing a specific language or locale without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON contains user-facing natural-language fields such as scorecard labels, summary, evidence, and next steps exclusively in Chinese. Because the file provides no documented locale constraint or user opt-in, it can violate a language/locale policy that requires offering language choice or clearly documenting region-specific scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown template is entirely written in Chinese and presents the resume scoring result in a fixed locale-specific format. The file does not indicate that the language is selectable or limited to a justified region-specific context, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template headings and labels are entirely in Chinese, which establishes a fixed output language for the skill. The file does not indicate that Chinese is optional, user-selected, or required for a justified region-specific context, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The template explicitly renders multiple categories of candidate personal data, including name, location, education, current title, company, and a resume excerpt. In a hiring workflow this may be expected, but exposing and distributing this data without any privacy notice, minimization controls, or guidance on safe handling increases the risk of unnecessary disclosure, over-sharing in chat tools, and downstream privacy noncompliance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON skill content presents summaries, interview questions, red flags, assumptions, and next steps only in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This plain-text skill file presents the entire content exclusively in Chinese and does not offer any language or locale choice. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This plain-text file uses a single enforced language throughout and does not indicate that Chinese is required, optional, or targeted to a specific locale. Under the language/locale policy rule, forcing one language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains user-facing natural language exclusively in Chinese, and there is no indication that the skill is region-specific or that users can opt into another language. Under the language/locale policy rule, forcing a specific language without user choice can be a policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.