Back to skill

Security audit

Resume Builder

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward resume-writing assistant that asks for expected resume details and does not include code, hidden actions, persistence, or external data access.

Before using it, decide whether you want to include real contact details in the chat. You can provide placeholders or skip phone/email until you are ready to finalize the resume.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly asks for sensitive personal contact information such as full name, phone number, and email without any privacy notice, minimization guidance, or warning that these details are optional. This creates unnecessary exposure of personally identifiable information and increases the risk of oversharing, downstream retention, or reuse in contexts the user may not expect.

Static analysis

No suspicious patterns detected.