Back to skill

Security audit

第三阶段:面试分析报告生成

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent HR interview-report generator, but it handles sensitive candidate data without enough privacy and consent guardrails.

Install only if users will run it inside an approved HR process. Use authorized candidate materials, minimize unnecessary personal data, store reports in approved systems, avoid cloud OCR unless it is approved for candidate records, and perform reference or background checks only with proper consent and legal review.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill is designed to ingest and process highly sensitive candidate data, including resumes, application forms, interview notes, compensation expectations, and background-check inputs, yet it provides no privacy, confidentiality, retention, minimization, or consent guidance. In an HR context, this materially increases the risk of unauthorized exposure, over-collection, improper sharing, or noncompliant handling of personal and potentially regulated employment data.

Static analysis

No suspicious patterns detected.