Back to skill

Security audit

Recruiting Resume Screening

Security checks for vulnerabilities and agentic risk

Overview

The resume-screening skill is mostly coherent, but it asks agents to search old local/cache data and persistently change its own screening rules, which could expose private resumes or alter future evaluations.

Review before installing. Use this only in a constrained workspace with files explicitly provided or confirmed for the current screening task. Do not allow automatic searches of Downloads, attachment caches, local notes, or temp directories for prior resumes. Install PDF dependencies in an isolated, pinned environment, clean up plaintext extracted resumes after use, and treat feedback-driven rule changes as proposals requiring maintainer review.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
batch-screening.md:42
Finding

Overbroad Search of Historical Conversations and Local Attachment Directories

Content
View full analysis

Vulnerability Details

File Location: batch-screening.md, lines 42-45
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: Medium

Vulnerable Instructions

text
1. Use conversation search or local notes to recover the position name, job-description filename, and candidate list from the previous screening.
2. Search local cache directories for historical attachments:
   - ~/Downloads/ or the conversation tool's attachment cache directory
   - Temporary directories commonly used by the user, according to the current agent environment

The excerpt above is an English translation of the original instructions at the specified location.

Technical Analysis

The Skill directs the agent to search historical conversations, local notes, the user's general Downloads directory, attachment caches, and commonly used temporary directories when reconstructing an earlier screening batch.

These locations are broader than the files explicitly provided or authorized for the current task. They may contain unrelated resumes, job descriptions, personal documents, or files belonging to other sessions. Searching them by default violates least-privilege and purpose-limitation principles.

The risk is amplified because resumes contain personal data, including names, contact details, education history, employment history, and potentially other sensitive information. Filename or keyword filtering does not establish authorization to access or process a file.

Attack Path

  1. An attacker or ordinary user asks the Skill to re-evaluate a previous candidate batch.
  2. The Skill attempts to reconstruct the batch through conversation search or local notes.
  3. It searches broad filesystem locations such as ~/Downloads/, attachment caches, and temporary directories.
  4. The search discovers files that were not explicitly supplied or authorized for the current request.
  5. Unrelated resumes or job descriptions may be extracted, indexe ...[truncated 747 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require the user to identify or re-upload the exact historical files before processing.
  2. Restrict automatic searches to a dedicated Skill workspace containing only files authorized for the current task.
  3. Do not search general-purpose locations such as ~/Downloads/, local notes, or global attachment caches.
  4. If historical recovery is necessary, present candidate file paths to the user and obtain explicit confirmation before opening them.
  5. Maintain a per-session file allowlist and reject files outside it.
  6. Separate each screening batch into a uniquely named temporary directory with restrictive permissions.
  7. Record the source and authorization status of every processed file.
  8. Apply retention controls and securely remove temporary extracted resume text after the task is complete.

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:163
Finding

Uncontrolled Persistent Modification of Skill Evaluation Rules

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 163
Vulnerability Type: T02: Agent Memory Poisoning
Risk Level: Medium

Vulnerable Instruction

text
User feedback updates this Skill's evaluation standards. Newly discovered risk patterns are added to red-flags-catalog.md. Major changes are written to EVOLUTION.md.

The excerpt above is an English translation of the original instruction at the specified location.

Technical Analysis

The Skill instructs the agent to turn user feedback into persistent changes to its evaluation standards and repository files. It provides no requirement for maintainer authorization, provenance validation, schema enforcement, security review, or testing.

User feedback is untrusted input. Allowing it to alter persistent screening rules creates a memory-poisoning channel: a user can propose biased, inaccurate, or malicious criteria that continue to influence later sessions and other users.

Because the affected files define candidate risk indicators and evaluation behavior, poisoned content could systematically alter hiring recommendations. Writing a change to an evolution log does not make the underlying change trustworthy.

Attack Path

  1. A malicious user completes a screening session and submits crafted feedback.
  2. The feedback proposes a new evaluation standard or alleged candidate risk pattern.
  3. Following the Skill instruction, the agent writes the proposed rule into the Skill, red-flags-catalog.md, or related persistent files.
  4. No maintainer review or validation occurs.
  5. A later user invokes the Skill for another candidate batch.
  6. The poisoned rule is loaded as trusted Skill guidance.
  7. Candidate scores, risk classifications, rankings, or interview recommendations are manipulated by the attacker's persistent rule.

Impact Assessment

The attacker may influence persistent application-level state and future evaluation behavior. The finding does not demonstrate OS-level pri ...[truncated 464 chars]

Remediation
View remediation

Remediation Suggestions

  1. Treat user feedback only as a proposed change, not as authorization to edit Skill files.
  2. Store proposals in a separate review queue that is not loaded as trusted instructions.
  3. Require explicit approval by an authorized maintainer before modifying evaluation rules.
  4. Record the proposer, source session, rationale, review decision, and exact diff for every accepted change.
  5. Validate changes against an approved schema and prohibit executable instructions or unrelated operational directives.
  6. Add regression tests to detect scoring drift, discriminatory criteria, and conflicts with existing policies.
  7. Use signed or access-controlled releases for production Skill content.
  8. Prevent normal runtime agents from writing to installed Skill files.
  9. Provide a rollback mechanism for previously accepted rule changes.

T08 · Insecure Dependencies

Warning
Location
pdf-extraction.md:15
Finding

Unpinned Third-Party PDF Parsing Dependencies

Content
View full analysis

Vulnerability Details

File Location: pdf-extraction.md, line 15
Additional Location: scripts/resume_pdf_extract.py, line 16
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Instructions

bash
python3 -m pip install --user pymupdf pdfplumber pdfminer.six
bash
pip install --user pymupdf pdfplumber pdfminer.six

Technical Analysis

The project recommends installing three Python packages without version constraints, integrity hashes, a lockfile, or an approved package-index configuration. As a result, the actual code installed can change after the Skill has been reviewed.

The listed package names appear consistent with the intended PDF libraries, and the audit found no evidence that they are deliberately typosquatted. The vulnerability is therefore the mutable and unverifiable dependency resolution process rather than a confirmed malicious package.

These libraries parse untrusted PDF files and execute within the user's Python process. A compromised release, malicious upstream update, dependency takeover, or newly introduced vulnerability could therefore affect the host when the extraction script imports a library or parses a crafted resume.

The use of --user installs packages into the user's persistent Python environment. This can affect other Python applications using the same environment and makes isolation and rollback more difficult.

Attack Path

  1. A user follows the documented installation command.
  2. pip resolves the latest available package and transitive dependency versions at installation time.
  3. A compromised or vulnerable release is retrieved because no reviewed version or hash is enforced.
  4. The extraction script imports the installed package.
  5. Malicious installation or import-time code executes, or a crafted PDF triggers a parser vulnerability.
  6. Code runs with the privileges of the user executing the Skill.

Impact Assessment

A compromised dependency ...[truncated 617 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin all direct and transitive dependencies to reviewed versions.
  2. Require cryptographic hashes, for example through a hash-locked requirements file.
  3. Generate and commit a lockfile using an appropriate dependency-management tool.
  4. Install dependencies inside a dedicated virtual environment or isolated container rather than with --user.
  5. Configure an approved package index and disable untrusted extra indexes.
  6. Regularly scan pinned dependencies for published vulnerabilities.
  7. Test upgrades in a controlled environment before updating the lockfile.
  8. Run PDF parsing with minimal filesystem and network permissions.
  9. Consider sandboxing parser processes and applying file-size, page-count, memory, and execution-time limits to untrusted PDFs.
  10. Update both documentation locations so they reference the same reviewed installation procedure.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description promises a resume-screening capability: evaluating candidates against a JD, ranking them, surfacing suspicious points in resumes, and generating interview questions. The supplied code does not do those tasks. Instead, it is a preprocessing utility for resume PDFs: it tries several extraction libraries, cleans noisy OCR/text output, computes a heuristic score indicating extraction quality and whether the text looks like a resume, and writes extracted text and summary metadata. This could support a downstream screening workflow, but on its own it does not perform the declared screening, ranking, or interview-question generation behaviors. Therefore the description materially overstates and misrepresents the actual code's purpose.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill directs use of a local extraction script that writes outputs such as summary.json, .txt files, and Markdown indexes, but it declares no tool scope or permissions boundary. In an agent environment, undeclared file-write capability can lead to unexpected filesystem modifications, leakage of sensitive resume data into uncontrolled locations, or execution paths that users and platform policy did not explicitly authorize.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The markdown explicitly requires '中文输出', which forces a specific language for all user-facing reports. Under the stated policy, locale or language constraints should either be optional, user-selected, or clearly justified as region-specific; this file does not present it as an opt-in choice.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Natural-language instructions to recover prior materials from conversation search, local notes, and cache directories create a data retrieval channel across past sessions. In the context of resume screening, this is especially risky because candidate materials contain PII, and the agent may accidentally surface another candidate's resume, a different company's JD, or other historical artifacts not intended for the current task.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to search prior conversations, local notes, Downloads, and cache directories to recover historical candidate resumes and JD files. That expands access beyond the current user-provided working set and creates a clear risk of pulling in unrelated or stale personal data from past sessions, leading to cross-session data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instructions tell the agent to inspect historical attachments and local cache locations without any user-facing disclosure or consent step. Because resumes and JD files commonly contain sensitive personal and business information, silent retrieval from prior storage locations undermines user expectations and increases privacy violation risk even if the intent is operational convenience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file title and all user-facing template content are written in Chinese, indicating the skill is designed to produce reports in a specific language. There is no visible opt-in, alternative language option, or justification that this is a region-specific tool, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guidance explicitly directs writing extracted resume text and summary artifacts to disk, and resumes commonly contain highly sensitive personal data such as names, contact details, employment history, and education records. Without retention limits, access controls, redaction, or privacy handling guidance, operators may leave plaintext PII in temporary or shared locations, increasing risk of unauthorized disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains only Chinese instructions and does not indicate that the user can choose another language or that the skill is intentionally restricted to Chinese-speaking users. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s natural-language description states that the tool is for 'Chinese resume screening,' and the scoring logic is further described as tuned for Chinese resumes. This imposes a locale/language-specific constraint in user-facing text without any opt-in, alternative locale support, or explicit policy justification such as a region-specific compliance requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

These comments describe the extraction/scoring behavior as specifically tuned for Chinese resumes, which is a natural-language locale restriction covered by the policy rule. The file does not pair this with a documented user choice or a clear justification for enforcing that locale specialization.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/resume_pdf_extract.py (reported line 57)May include surrounding context.

python
def _try_import(module: str):
    try:
        return __import__(module)
    except Exception:
        return None

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/resume_pdf_extract.py (reported line 288)May include surrounding context.

python
module_name = {"fitz": "fitz", "pdfplumber": "pdfplumber",
                       "pdfminer": "pdfminer.high_level"}[name]
        try:
            __import__(module_name.split(".")[0])
            available.append(name)
        except Exception:
            pass

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This file presents all instructions and scoring criteria only in Chinese, with no indication that users may choose another language or that the Chinese-only constraint is required for a region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The file presents all user-facing instructions in Chinese and does not indicate that the skill is region-specific or that users may choose another language. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.