T09 · Insecure Skill Coding Practices
- Location
shared/access.md:21- Finding
Low-Entropy Access-ID Reused as a Webhook HMAC Secret
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed CV-publishing skill, but some documented flows can publish personal data without final human approval and rely on permanent bearer claim links.
Review this skill before installing. It is not evidence of malware, but use it only when users clearly understand that their CV data is sent to talent.de and can create a persistent public profile. Prefer HITL with explicit final approval, avoid fail-open timeout behavior, protect claim links like passwords, and avoid webhook callbacks unless the Access-ID/HMAC secret design is strengthened or otherwise acceptable for your risk level.
shared/access.md:21Low-Entropy Access-ID Reused as a Webhook HMAC Secret
SKILL.md:304Fail-Open HITL Timeout Can Publish Personal Data Without Final Approval
Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.
3. Each re-POST creates a **new CV** with a **new `cv_id`** — the previous one is abandoned
4. After **2 cycles** OR when `improvement_suggestions` is empty: **stop**
> **Do not loop indefinitely.** An agent that keeps re-posting creates duplicate CVs and wastes the requestor's time.
For `prefer_hitl` flows: after approval, the 201 is already quality-assessed (human reviewed the data). If suggestions appear, ask the requestor directly — do not restart the HITL flow.
The document instructs agents to send highly sensitive personal data—including full name, email, phone, location, employment history, education, social links, and optional certificates—to an external service endpoint, but provides no privacy notice, consent requirement, data minimization guidance, retention details, or warning that a public URL may be created. In the context of a CV-building skill, this is especially risky because users may assume the data is only being formatted locally, while the skill metadata explicitly indicates creation of a permanent public profile URL, increasing privacy and exposure risk.
The documentation explicitly supports skip_hitl: true, which allows publishing a CV without any human confirmation or approval step. In a workflow handling personal identity and public profile publication, this increases the risk of unintended disclosure, impersonation, or publishing incorrect sensitive data if an agent or automation path invokes the shortcut without clear user consent.
The documentation shows review URLs fixed to an English locale path, and no surrounding text indicates that language is selectable or user-driven. Under SQP-3, forcing a specific language or locale without opt-in can constitute a natural-language policy violation.
This example again presents the review flow in a fixed English locale and does not mention alternatives or user preference handling. Repeated locale-specific examples without clarification can imply that the skill forces English by default.
Lines L42-L44 describe the endpoint as returning human-readable error messages while immediately giving an example where a normally erroneous condition (taken slug) does not return an error at all and is silently corrected. This is an intent/documentation contradiction within the file because it describes error handling behavior inconsistently.
No suspicious patterns detected.