Back to skill

Security audit

CareerMax

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for CareerMax account workflows, but its setup executes an unpinned npm MCP toolkit that can change after review while using a CareerMax API key.

Install only if you trust the CareerMax npm package and are comfortable giving the MCP process access to your CareerMax account. Prefer a pinned, reviewed toolkit version, use a dedicated least-privileged CareerMax agent key, run it in a constrained environment, and rotate the key if you suspect package or environment compromise.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:66
Finding

Unpinned npm Package Is Downloaded and Executed Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 66
Vulnerability Type: Supply-chain exposure caused by unpinned remote package execution
Risk Level: High

Vulnerable Code:

sh
npx -y @careermax/agent-toolkit mcp

Technical Analysis

The documented setup command invokes npx without specifying an exact package version, lockfile, or integrity hash. Consequently, command behavior depends on whichever release of @careermax/agent-toolkit the npm registry resolves at execution time rather than on the code reviewed with this skill.

The -y option automatically accepts installation prompts. If the package, publisher account, release pipeline, or package-resolution path is compromised, a malicious release can be downloaded and executed without an additional interactive approval step. npm package lifecycle hooks and the package entry point can execute arbitrary code under the privileges of the user running the command.

The skill requires CAREERMAX_API_KEY to be present in the environment. A malicious package executed by this command could therefore attempt to read that credential and any other data accessible to the process.

Attack Path

  1. An attacker compromises the npm publisher account, release pipeline, package source, or another relevant supply-chain component for @careermax/agent-toolkit.
  2. The attacker publishes a malicious release that becomes the version selected by the unpinned package reference.
  3. A user follows the setup instructions and runs npx -y @careermax/agent-toolkit mcp.
  4. npx retrieves the attacker-controlled release and executes its lifecycle scripts or command entry point.
  5. The payload runs with the invoking user's privileges and may read environment variables, including CAREERMAX_API_KEY, access user-readable files, contact remote systems, or alter local data.

Impact Assessment

Successful exploitation could provide arbitrary code execution wit ...[truncated 668 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the toolkit to an exact, reviewed version rather than allowing npm to select the latest release:

    sh
    npx -y @careermax/agent-toolkit@<reviewed-exact-version> mcp
    
  2. Do not assume the skill's own version is also a valid toolkit version. Select and document a package version that has been independently reviewed and tested.

  3. Prefer installing through a lockfile-backed project using npm ci, with the lockfile committed and reviewed, instead of performing an ad hoc remote installation on each invocation.

  4. Verify package provenance and integrity using npm registry integrity metadata, trusted publishing or provenance attestations, and an approved package source.

  5. Remove -y where interactive review is operationally appropriate so unexpected installation activity is not silently accepted.

  6. Run the MCP process in a restricted environment with only the required credential, minimal filesystem access, and controlled outbound network access.

  7. Use a dedicated, least-privileged CareerMax API key and establish rotation and revocation procedures in case dependency compromise is suspected.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description says to use CareerMax when the user wants to 'review their career context, manage their job pipeline, improve career materials, prepare for interviews, find referrals, or build skills,' which is a wide and ambiguous set of triggers. It does not define clear boundaries or negative examples for when the skill should or should not activate, increasing the risk of unintended invocation on ordinary career advice requests.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The setup instruction runs npx -y @careermax/agent-toolkit mcp without pinning an exact package version. This allows whatever version is latest at install time to be fetched and executed, creating a supply-chain risk where a compromised or malicious upstream release could execute code in the agent environment and access sensitive data such as the CareerMax API key.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.