Back to skill

Security audit

resume-jd-matcher

Security checks for vulnerabilities and agentic risk

Overview

This resume-matching skill has a coherent purpose, but it uses sensitive applicant data with under-scoped external processing and an unsafe entry point that loads code from outside the reviewed package.

Review carefully before installing. Do not use this with real candidate resumes until the external workspace import is removed, the exposed API keys are revoked and replaced with user-provided secrets, and the skill adds explicit consent, provider disclosure, data minimization, and retention controls for resume data.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T07 · Tool Hijacking and Spoofing

Error
Location
main.py:11
Finding

Execution of Mutable External Workspace Code Through the Skill Entry Point

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/config_resume_match.yaml:25
Finding

Plaintext API Credentials Committed in the Distributed Configuration

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/resume_match.py:416
Finding

Complete Resume Data and API Credentials Can Be Sent to an Arbitrary Configured Endpoint

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/skill_handler.py:157
Finding

Prompt Injection Through Untrusted Resume and Job Description Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (35)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README describes AI-based matching and API mode but does not clearly warn that resumes and job descriptions—both likely containing sensitive personal and business information—may be transmitted to an external AI or API provider. Users may therefore process highly sensitive data without informed consent, creating privacy, confidentiality, and compliance risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个可实际批量解析简历、与 JD 进行 AI 匹配并输出 Excel 报告的技能。但该代码片段本质上是演示脚本:它确实会读取本地 JD/简历文件并提取文本,也会做非常初步的基于文件夹名的 JD 匹配;然而真正的 AI 分析部分(sessions_spawn 调用)被注释掉,没有实际执行任何子代理匹配任务,tasks_submitted 也不会被填充。后续“生成 Excel 报告”步骤同样只是打印输出路径,没有创建或写入 Excel 文件。因此,代码的实际行为与声明中的核心承诺存在实质性不一致。另一个次要差异是代码依赖固定 Windows 本地路径访问文件资源,这种资源访问假设在声明中没有体现。综合来看,应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

该代码的核心目的与声明前半部分基本一致:批量读取简历和 JD,并进行 AI 匹配分析。但声明中特别强调“生成结构化匹配报告(Excel)”,而提供的代码只负责读取文件、拆分 JD 要求、调用子 Agent 分析、轮询收集结果和写日志,最终返回内存中的结果列表,没有看到任何 Excel 生成、表格结构化整理、保存报告文件的实现。因此描述高估了已实现功能,属于明显的描述-行为不一致。其余如日志、配置读取、目录扫描属于支撑性实现细节,不是主要不匹配点。

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is designed to process resumes, which commonly contain highly sensitive personal data, yet the documentation provides no warning that this data may be parsed, exported to Excel, and written to logs. In context, this omission is more dangerous because the data category is inherently sensitive and the workflow is batch-oriented, increasing the scale of potential privacy leakage or policy noncompliance.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description suggests local parsing and matching, but the code supports an API mode that can send full resume and JD contents to third-party providers. Because resumes contain highly sensitive personal data, this is a material data-flow capability that is not transparently disclosed and can violate user expectations, privacy requirements, or internal handling policies.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This function constructs prompts containing complete resume text and job requirements and submits them to an externally configured multi-provider API endpoint. That is a sensitive exfiltration path for personal and potentially confidential hiring data, especially because the endpoint and provider are configuration-driven and may vary in trust, geography, and retention practices.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrase is broad enough that the skill may activate on loosely related user requests involving local resume directories, increasing the chance of unintended bulk processing of sensitive personal data. In a skill that handles resumes and job descriptions, accidental invocation can expose private documents to downstream parsing and AI analysis without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents file reading, file writing, and external API usage, but does not declare any explicit tool scope such as permissions or allowed-tools. In an agent ecosystem, missing scope declarations can cause overly broad or implicit capability grants, making sensitive local resume data and generated outputs easier to access or exfiltrate than users expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase is broad enough that normal user conversation such as asking for help matching resumes in a directory could invoke the skill unintentionally. Because this skill processes sensitive resumes in bulk and may write reports/logs, accidental activation could expose personal data, initiate undesired file access, or send data to downstream models/APIs without deliberate user intent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The documented API mode sends resume and JD content to an external model endpoint, which is a real data egress risk when handling personal information. In this skill context, the external transmission is more sensitive than usual because resumes may include contact details, employment history, education, and other regulated personal data, and users are not prominently warned about that transfer.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

tencent: name: "腾讯 Hunyuan" api_key: "sk_xxxxx" api_url: "https://api.hunyuan.tencent.com/v1/chat/completions" model: "hunyuan-t1"

text

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description is written entirely in Chinese and presents the skill's behavior in a single fixed language, with no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking context. This creates a natural-language locale policy concern because the skill appears to impose a specific language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill processes resumes, which commonly contain highly sensitive personal data, and writes derived results to disk without any notice, consent flow, retention guidance, or output access controls. In this context, silent bulk ingestion and persistence of applicant data increases privacy and compliance risk, especially on a shared workstation or multi-user agent environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file is entirely oriented around Chinese-language labels, comments, output columns, and evaluation categories, with no indication that users may select another language or that the skill is intentionally limited to a China-specific workflow. This is a natural-language locale constraint visible in the configuration and falls under policy concerns when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

技能清单描述强调的是批量解析简历、与 JD 匹配并生成 Excel 报告,但该配置在文档层面明确声明了独立的外部 API 模式,并列出多个第三方服务提供商。将候选人简历内容发送到外部模型服务属于额外的数据外发能力;如果该能力未在技能描述中明确说明,会造成用户对处理边界的理解偏差。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This configuration embeds multiple third-party model endpoints and includes live-looking API credentials for some providers, creating a real risk that sensitive resume contents will be transmitted off-platform without clear user awareness. Because resumes commonly contain PII and career history, undisclosed or poorly governed transmission to external vendors can cause privacy, compliance, and data-handling violations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
99% confidence
Finding

This entry contains a real external API endpoint alongside a hardcoded Tencent-style secret key, enabling unauthorized use of the provider account and facilitating transmission of sensitive resume/JD data to a third party. Exposure of embedded credentials in a skill repository is a direct secret-management failure and can lead to billing abuse, account compromise, and privacy incidents.

Content

Scanner excerpt · references/config_resume_match.yaml (reported line 40)May include surrounding context.

yaml
tencent:
      name: "腾讯"
      api_key: "sk-sp-sq7Y7eo9L0vgFpuESFLq5YsQB8qumjDnwOPeciB9v3F0BSKv"
      api_url: "https://api.lkeap.cloud.tencent.com/coding/anthropic/v1/messages"
      model: "hunyuan-t1"
      description: "腾讯 Hunyuan-T1,适合长文本分析"

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This configuration enables outbound transmission to DeepSeek if api mode is used, which is security-relevant because resumes may contain sensitive personal data. Although the shown key is a placeholder rather than a live secret, the egress path still creates privacy and compliance risk if enabled without proper notice and controls.

Content

Scanner excerpt · references/config_resume_match.yaml (reported line 64)May include surrounding context.

yaml
deepseek:
      name: "DeepSeek"
      api_key: "YOUR_DEEPSEEK_API_KEY"
      api_url: "https://api.deepseek.com/v1/chat/completions"
      model: "deepseek-chat"
      description: "DeepSeek-V3,开源模型,成本低"

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This Moonshot endpoint similarly establishes a ready external transmission path for sensitive resume and JD content. Even with a placeholder key, the configuration makes remote processing easy to enable, which is risky in a resume-matching skill where personal data exposure is a primary concern.

Content

Scanner excerpt · references/config_resume_match.yaml (reported line 72)May include surrounding context.

yaml
moonshot:
      name: "月之暗面"
      api_key: "YOUR_MOONSHOT_API_KEY"
      api_url: "https://api.moonshot.cn/v1/chat/completions"
      model: "moonshot-v1-8k"
      description: "Kimi,长上下文支持好"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This manifest/config template uses Chinese throughout comments, labels, and descriptions, which effectively forces a specific language for users interacting with the skill configuration. The policy allows locale constraints only when they are clearly documented and justified or when users are given a choice, neither of which appears here.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The configuration explicitly sends resume and JD content to third-party cloud LLM endpoints, and the same file states resumes may be sent in full with no character limit. Because resumes commonly contain sensitive personal data, this creates a real data-exposure and privacy risk if operators use external providers without consent, minimization, or data-handling safeguards. In this skill context, the risk is elevated because the core workflow involves bulk processing of personal documents.

Content

Scanner excerpt · references/config_template.yaml (reported line 24)May include surrounding context.

yaml
tencent:
      name: "腾讯 Hunyuan"
      api_key: "YOUR_TENCENT_API_KEY"
      api_url: "https://api.lkeap.cloud.tencent.com/coding/anthropic/v1/messages"
      model: "hunyuan-t1"
      description: "腾讯 Hunyuan-T1,适合长文本分析"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code includes natural-language instructions, status messages, and usage guidance entirely in Chinese, such as the module docstring and printed runtime messages. Because the file does not provide any opt-in or alternative locale, it imposes a specific language on users, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Unbounded Output

Medium
Category
Output Handling
Confidence
80% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · scripts/resume_match.py (reported line 68)May include surrounding context.

python
API_KEY = None
    API_URL = None
    MODEL = None
    MAX_TOKENS = None
    TIMEOUT = 60

# 路径配置

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code persistently caches parsed resume and JD text as JSON files alongside source documents, but this storage behavior is not reflected in the skill description. This creates silent at-rest retention of sensitive applicant data, increasing exposure if the workstation, shared folders, backups, or downstream tools are accessed by unauthorized parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The network submission path sends resume content to an external API without any user-facing warning, confirmation, or contextual disclosure at runtime. In a resume-processing skill, this omission is risky because users may reasonably expect local handling of applicant data and may not realize regulated or confidential content is leaving the environment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The code performs an outbound HTTP POST to a configurable API endpoint carrying full prompt contents, which include resume and JD text. External transmission itself is not always forbidden, but in this context it is sensitive because the payload contains personal data and the destination is configurable without visible safeguards such as allowlisting or explicit user approval.

Content

Scanner excerpt · scripts/resume_match.py (reported line 464)May include surrounding context.

python
}
    
    try:
        response = requests.post(API_URL, headers=headers, json=data, timeout=TIMEOUT)
        if response.status_code == 200:
            result = response.json()
            if 'choices' in result:

Static analysis

No suspicious patterns detected.