Back to skill

Security audit

AI产品经理简历维护

Security checks for vulnerabilities and agentic risk

Overview

This resume skill is mostly purpose-aligned, but its local dashboard can expose sensitive resume content through unsafe browser rendering and unpinned external scripts.

Review before installing. The skill appears intended for resume maintenance rather than theft or damage, but users should avoid opening or exporting dashboards built from untrusted resume content until the dashboard escapes embedded JSON, avoids unsafe innerHTML, and either bundles its browser dependencies locally or discloses and pins CDN use with integrity checks.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/render_dashboard.py:236
Finding

Stored XSS Through Unescaped JSON Embedded in a Script Element

Content
View full analysis
{payload_json} ``` ### Technical Analysis The dashboard generator serializes resume data with `json.dumps()` and directly embeds the result in an HTML ``. Consequently, attacker-controlled resume content containing a payload such as the following can terminate the JSON data element and introduce a new executable script: ```html ``` The affected payload includes `onepage_md`, project-label statistics, gaps, and the generation timestamp. The resume and derived fields originate from files that may contain user-provided or third-party-provided content. The fact that the script element uses `type="application/json"` does not mitigate the issue: the HTML parser recognizes the closing `` sequence before JavaScript or JSON parsing occurs. ### Attack Path 1. An attacker supplies a crafted resume, work log, project label, or gap value. 2. The malicious value is propagated into the dashboard payload. 3. `_render_html()` serializes the value through `json.dumps()` without HTML-safe escaping. 4. The serialized payload is inserted directly into the `resumeData` script element. 5. The user opens `resume-dashboard.html`, or `export_pdf.py` loads it through Playwright. 6. The injected closing tag terminates the data element, and the attacker's new script executes in the dashboard's browser context. ### Impact Assessment Successful exploitation permits attacker-controlled JavaScript execution in the local dashboard page and in the headless ...[truncated 660 chars]
Remediation
View remediation
` as `\u003e` - `&` as `\u0026` - U+2028 as `\u2028` - U+2029 as `\u2029` 3. Prefer writing the payload to a separate local JSON file and loading it as data rather than embedding it in HTML. 4. Add a restrictive Content Security Policy that disallows inline scripts and limits network destinations. 5. Add regression tests containing ``, HTML tags, event handlers, and Unicode separator characters. 6. Treat all resume, work-log, project-label, and gap content as untrusted input regardless of whether it comes from a local file. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/render_dashboard.py:261
Finding

Stored DOM XSS Through Unsanitized Gap and Project-Label Rendering

Content
View full analysis
`
  • ${gap}
  • `).join(''); ``` ```javascript container.innerHTML = entries.map(([label, count]) => { const pct = Math.round((count / max) * 100); return `
    ${label} ${count} 条
    `; }).join(''); ``` ### Technical Analysis The dashboard interpolates `gap` and `label` values into HTML template strings and assigns the resulting strings to `innerHTML`. These values originate from resume and points-pool Markdown files and are not escaped before reaching the DOM sink. Although DOMPurify is used when rendering the main Markdown pane, that sanitization applies only inside `mdToHtml()`. It does not protect the separate gap and project-label rendering paths. An attacker can therefore place HTML elements or event-handler attributes into a project label or a `[待补数据:...]` marker. When the browser parses the generated string assigned to `innerHTML`, attacker-controlled markup becomes part of the live document. A payload using an event-capable element can execute JavaScript when the relevant browser event is triggered. ### Attack Path 1. An at ...[truncated 1230 chars]
    Remediation
    View remediation

    T08 · Insecure Dependencies

    Warning
    Location
    scripts/render_dashboard.py:101
    Finding

    Mutable Third-Party JavaScript Loaded From External CDNs Without Integrity Protection

    Content
    View full analysis
    ``` ```html ``` ### Technical Analysis The generated dashboard executes JavaScript retrieved from external CDNs whenever it is opened with network access. The Tailwind and Marked resources are not pinned to exact immutable versions. None of the three resources uses Subresource Integrity. Even though DOMPurify includes a version in its URL, the browser has no integrity hash with which to verify the downloaded bytes. This creates a supply-chain trust boundary in which the effective executable dashboard code can change after the Skill package has been reviewed. A compromised CDN, package account, dependency distribution path, or mutable upstream resource could return hostile JavaScript. The dashboard embeds potentially sensitive resume information in its DOM. Any compromised dependency executing in the page can read that information and make outbound requests. The mobile PDF exporter also loads this page in headless Chromium and waits for network activity, exposing that workflow to the same dependency risk. ### Attack Path 1. The user generates `resume-dashboard.html`. 2. The user opens the dashboard or invokes mobile PDF export while network access is available. 3. The browser requests executable JavaScript from Tailwind's CDN and jsDelivr. 4. A compromised or unexpectedly modified resource is returned. 5. The browser executes the third-party code with access to the dashboard DOM. 6. The hostile dependency reads, alters, or transmits resume information or manipulates the generated PDF. ### Impact As ...[truncated 545 chars]
    Remediation
    View remediation
    Vulnerability Patterns
    • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
    • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
    • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
    • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
    • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
    Findings (8)

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    97% confidence
    Finding

    The skill advertises itself as a resume-maintenance hub, but it also invokes local scripts to render dashboards and export PDFs. This mismatch weakens user and policy expectations, making it easier to smuggle higher-risk behaviors under a benign description and causing agents to execute code or touch additional output resources the user did not clearly consent to.

    Content

    No source excerpt is available for this finding.

    Undeclared Tool Scope

    Medium
    Category
    MCP Least Privilege
    Confidence
    91% confidence
    Finding

    The skill performs file reads and writes across a fixed workspace but does not declare an explicit tool scope or permission boundary. That creates an authorization ambiguity: an agent may treat the skill as harmless text while still being induced to modify local files, increasing the risk of unintended filesystem access or overbroad execution.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    97% confidence
    Finding

    The description states the skill is used to generate or update a “中文一页纸简历,” which imposes a specific language choice in the skill behavior. There is no indication that the user can choose another language or that the Chinese-only constraint is an explicitly justified regional requirement.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The skill mandates creating directories and writing multiple files but does not prominently warn users that it will modify workspace contents. In a file-capable agent environment, hidden or implicit persistence is risky because a casual request can result in durable changes, overwritten structure, or sensitive resume material being stored without informed consent.

    Content

    No source excerpt is available for this finding.

    Vague Triggers

    Medium
    Category
    Not specified by scanner
    Confidence
    92% confidence
    Finding

    The trigger phrases are broad and map ordinary language like '更新简历' or '生成一页简历' directly to a skill that reads and writes files. This can cause accidental activation in unrelated conversations, leading to unintended file modifications or processing of workspace content without sufficiently specific user intent.

    Content

    No source excerpt is available for this finding.

    Intent-Code Divergence

    Medium
    Category
    Not specified by scanner
    Confidence
    97% confidence
    Finding

    The script states the dashboard is local and 'won't upload anything', but the generated HTML loads Tailwind, Marked, and DOMPurify from third-party CDNs. Opening the page causes the browser to contact external servers, leaking access metadata and creating a supply-chain risk if CDN-hosted JavaScript is tampered with; because the page renders resume content, this is especially sensitive in a resume-management skill.

    Content

    No source excerpt is available for this finding.

    Context-Inappropriate Capability

    Medium
    Category
    Not specified by scanner
    Confidence
    94% confidence
    Finding

    A local resume dashboard should not require network access to function, yet the generated HTML pulls executable scripts from external CDNs. This expands the attack surface from a local file viewer to remote code execution in the browser context if a CDN asset is compromised, and unnecessarily exposes that the user opened a page associated with resume data.

    Content

    No source excerpt is available for this finding.

    Description-Behavior Mismatch

    Low
    Category
    Not specified by scanner
    Confidence
    83% confidence
    Finding

    The manifest describes extracting logs, deduplicating resume points, maintaining a points pool, generating/updating a one-page Chinese resume, and outputting a gap list. This script instead renders and writes a visualization dashboard HTML file for previewing artifacts, which is a related but distinct behavior not reflected in the stated description.

    Content

    No source excerpt is available for this finding.

    Static analysis

    No suspicious patterns detected.