Back to skill

Security audit

Cover Letter Writer

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent CareerMax cover-letter helper, but its setup runs a mutable npm package with the user's CareerMax API key.

Review this skill before installing. It appears purpose-aligned, but prefer a pinned and reviewed @careermax/agent-toolkit version, use a narrowly scoped CareerMax API key if available, and rotate the key if you later discover the package or account was compromised.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:45
Finding

Unpinned Remote npm Package Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 45–51
Vulnerability Type: Unpinned third-party dependency executed through npx
Risk Level: Medium

Complete Code Snippet:

bash
CAREERMAX_API_KEY="cmx_live_..." npx -y --package @careermax/agent-toolkit@latest careermax-mcp
bash
npx -y --package @careermax/agent-toolkit@latest careermax cover-letter generate --job-id <id>

Technical Analysis

The documented commands use npx -y to download and execute the external @careermax/agent-toolkit npm package without interactive confirmation. The MCP command explicitly selects the mutable @latest tag, while the CLI command also omits an exact version. Consequently, the code executed by future invocations can differ from the code available when this skill was reviewed.

The project contains no lockfile, integrity hash, pinned package version, or local implementation that would allow the executed dependency to be reproducibly verified. In the MCP command, the downloaded process also receives CAREERMAX_API_KEY through its environment. The package name and scope are consistent with the declared CareerMax integration, so the reviewed evidence does not establish malicious intent, dependency confusion, or typosquatting. The vulnerability is the unsafe, unpinned supply-chain execution pattern.

Attack Path

  1. An attacker compromises the npm package, its maintainer account, publishing credentials, or release process.
  2. The attacker publishes a malicious release and makes it the version resolved by @latest, or otherwise the default version selected by the unversioned command.
  3. A user invokes one of the commands documented in SKILL.md.
  4. npx -y downloads and executes the attacker-controlled package without requesting confirmation.
  5. The package runs with the invoking user's operating-system permissions.
  6. During MCP execution, the malicious process can access `CAREERMAX ...[truncated 817 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace @latest and the unversioned package reference with an exact, reviewed version, for example @careermax/agent-toolkit@X.Y.Z.
  2. Use a committed lockfile and reproducible installation workflow where the deployment model permits it.
  3. Verify npm package provenance, publisher identity, signatures or attestations, and registry integrity before approving each version.
  4. Record and validate the expected package integrity hash when supported by the installation workflow.
  5. Do not update the pinned version automatically. Require security review and testing before each dependency upgrade.
  6. Run the MCP server and CLI in a sandbox or container with minimal filesystem access, restricted network destinations, and no unnecessary operating-system privileges.
  7. Provide CAREERMAX_API_KEY only to a verified process, use a narrowly scoped credential if supported, and establish rotation and revocation procedures.
  8. Avoid npx -y for security-sensitive execution when an installed, reviewed, and integrity-verified binary can be used instead.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs users to launch an npm package with npx ... @latest, which fetches and executes the newest published code at runtime without a fixed version. If the package is compromised, a malicious release is published, or the dependency chain is hijacked, the agent could run attacker-controlled code and expose the CAREERMAX_API_KEY or other local data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The CLI example also uses npx ... @latest, creating the same supply-chain risk: execution depends on whatever code is currently published under that package name. In this skill's context, the command is meant to run with access to a live API key and career-related user data, which increases the consequences of a malicious package update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.