Back to skill

Security audit

Digital Identity, CV & Resume Creator

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed CV-publishing skill, but some documented flows can publish personal data without final human approval and rely on permanent bearer claim links.

Review this skill before installing. It is not evidence of malware, but use it only when users clearly understand that their CV data is sent to talent.de and can create a persistent public profile. Prefer HITL with explicit final approval, avoid fail-open timeout behavior, protect claim links like passwords, and avoid webhook callbacks unless the Access-ID/HMAC secret design is strengthened or otherwise acceptable for your risk level.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
shared/access.md:21
Finding

Low-Entropy Access-ID Reused as a Webhook HMAC Secret

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:304
Finding

Fail-Open HITL Timeout Can Publish Personal Data Without Final Approval

Content
View full analysis
24h | `expired` | `default_action` applies automatically (`skip` or `abort`) | | Cancelled | Any time | `cancelled` | Human or system cancelled; no further submissions possible | ``` From `shared/privacy.md:7-14`: ```text ## Claim Tokens Each CV creation returns a `claim_token`. Treat it like a password: - Share only with the requestor — never with third parties - Anyone with the token can claim CV o ...[truncated 2783 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · SKILL.md (reported line 320)May include surrounding context.

md
3. Each re-POST creates a **new CV** with a **new `cv_id`** — the previous one is abandoned
4. After **2 cycles** OR when `improvement_suggestions` is empty: **stop**

> **Do not loop indefinitely.** An agent that keeps re-posting creates duplicate CVs and wastes the requestor's time.

For `prefer_hitl` flows: after approval, the 201 is already quality-assessed (human reviewed the data). If suggestions appear, ask the requestor directly — do not restart the HITL flow.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document instructs agents to send highly sensitive personal data—including full name, email, phone, location, employment history, education, social links, and optional certificates—to an external service endpoint, but provides no privacy notice, consent requirement, data minimization guidance, retention details, or warning that a public URL may be created. In the context of a CV-building skill, this is especially risky because users may assume the data is only being formatted locally, while the skill metadata explicitly indicates creation of a permanent public profile URL, increasing privacy and exposure risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation explicitly supports skip_hitl: true, which allows publishing a CV without any human confirmation or approval step. In a workflow handling personal identity and public profile publication, this increases the risk of unintended disclosure, impersonation, or publishing incorrect sensitive data if an agent or automation path invokes the shortcut without clear user consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The documentation shows review URLs fixed to an English locale path, and no surrounding text indicates that language is selectable or user-driven. Under SQP-3, forcing a specific language or locale without opt-in can constitute a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This example again presents the review flow in a fixed English locale and does not mention alternatives or user preference handling. Repeated locale-specific examples without clarification can imply that the skill forces English by default.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

Lines L42-L44 describe the endpoint as returning human-readable error messages while immediately giving an example where a normally erroneous condition (taken slug) does not return an error at all and is silently corrected. This is an intent/documentation contradiction within the file because it describes error handling behavior inconsistently.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.