T07 · Tool Hijacking and Spoofing
- Location
main.py:11- Finding
Execution of Mutable External Workspace Code Through the Skill Entry Point
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This resume-matching skill has a coherent purpose, but it uses sensitive applicant data with under-scoped external processing and an unsafe entry point that loads code from outside the reviewed package.
Review carefully before installing. Do not use this with real candidate resumes until the external workspace import is removed, the exposed API keys are revoked and replaced with user-provided secrets, and the skill adds explicit consent, provider disclosure, data minimization, and retention controls for resume data.
main.py:11Execution of Mutable External Workspace Code Through the Skill Entry Point
references/config_resume_match.yaml:25Plaintext API Credentials Committed in the Distributed Configuration
scripts/resume_match.py:416Complete Resume Data and API Credentials Can Be Sent to an Arbitrary Configured Endpoint
scripts/skill_handler.py:157Prompt Injection Through Untrusted Resume and Job Description Content
The README describes AI-based matching and API mode but does not clearly warn that resumes and job descriptions—both likely containing sensitive personal and business information—may be transmitted to an external AI or API provider. Users may therefore process highly sensitive data without informed consent, creating privacy, confidentiality, and compliance risk.
声明描述的是一个可实际批量解析简历、与 JD 进行 AI 匹配并输出 Excel 报告的技能。但该代码片段本质上是演示脚本:它确实会读取本地 JD/简历文件并提取文本,也会做非常初步的基于文件夹名的 JD 匹配;然而真正的 AI 分析部分(sessions_spawn 调用)被注释掉,没有实际执行任何子代理匹配任务,tasks_submitted 也不会被填充。后续“生成 Excel 报告”步骤同样只是打印输出路径,没有创建或写入 Excel 文件。因此,代码的实际行为与声明中的核心承诺存在实质性不一致。另一个次要差异是代码依赖固定 Windows 本地路径访问文件资源,这种资源访问假设在声明中没有体现。综合来看,应判定为描述与行为不匹配。
该代码的核心目的与声明前半部分基本一致:批量读取简历和 JD,并进行 AI 匹配分析。但声明中特别强调“生成结构化匹配报告(Excel)”,而提供的代码只负责读取文件、拆分 JD 要求、调用子 Agent 分析、轮询收集结果和写日志,最终返回内存中的结果列表,没有看到任何 Excel 生成、表格结构化整理、保存报告文件的实现。因此描述高估了已实现功能,属于明显的描述-行为不一致。其余如日志、配置读取、目录扫描属于支撑性实现细节,不是主要不匹配点。
The skill is designed to process resumes, which commonly contain highly sensitive personal data, yet the documentation provides no warning that this data may be parsed, exported to Excel, and written to logs. In context, this omission is more dangerous because the data category is inherently sensitive and the workflow is batch-oriented, increasing the scale of potential privacy leakage or policy noncompliance.
The skill description suggests local parsing and matching, but the code supports an API mode that can send full resume and JD contents to third-party providers. Because resumes contain highly sensitive personal data, this is a material data-flow capability that is not transparently disclosed and can violate user expectations, privacy requirements, or internal handling policies.
This function constructs prompts containing complete resume text and job requirements and submits them to an externally configured multi-provider API endpoint. That is a sensitive exfiltration path for personal and potentially confidential hiring data, especially because the endpoint and provider are configuration-driven and may vary in trust, geography, and retention practices.
The trigger phrase is broad enough that the skill may activate on loosely related user requests involving local resume directories, increasing the chance of unintended bulk processing of sensitive personal data. In a skill that handles resumes and job descriptions, accidental invocation can expose private documents to downstream parsing and AI analysis without sufficiently explicit user intent.
The skill documents file reading, file writing, and external API usage, but does not declare any explicit tool scope such as permissions or allowed-tools. In an agent ecosystem, missing scope declarations can cause overly broad or implicit capability grants, making sensitive local resume data and generated outputs easier to access or exfiltrate than users expect.
The trigger phrase is broad enough that normal user conversation such as asking for help matching resumes in a directory could invoke the skill unintentionally. Because this skill processes sensitive resumes in bulk and may write reports/logs, accidental activation could expose personal data, initiate undesired file access, or send data to downstream models/APIs without deliberate user intent.
The documented API mode sends resume and JD content to an external model endpoint, which is a real data egress risk when handling personal information. In this skill context, the external transmission is more sensitive than usual because resumes may include contact details, employment history, education, and other regulated personal data, and users are not prominently warned about that transfer.
tencent: name: "腾讯 Hunyuan" api_key: "sk_xxxxx" api_url: "https://api.hunyuan.tencent.com/v1/chat/completions" model: "hunyuan-t1"
The manifest description is written entirely in Chinese and presents the skill's behavior in a single fixed language, with no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking context. This creates a natural-language locale policy concern because the skill appears to impose a specific language without opt-in or documented justification.
The skill processes resumes, which commonly contain highly sensitive personal data, and writes derived results to disk without any notice, consent flow, retention guidance, or output access controls. In this context, silent bulk ingestion and persistence of applicant data increases privacy and compliance risk, especially on a shared workstation or multi-user agent environment.
The file is entirely oriented around Chinese-language labels, comments, output columns, and evaluation categories, with no indication that users may select another language or that the skill is intentionally limited to a China-specific workflow. This is a natural-language locale constraint visible in the configuration and falls under policy concerns when no opt-in or justification is provided.
技能清单描述强调的是批量解析简历、与 JD 匹配并生成 Excel 报告,但该配置在文档层面明确声明了独立的外部 API 模式,并列出多个第三方服务提供商。将候选人简历内容发送到外部模型服务属于额外的数据外发能力;如果该能力未在技能描述中明确说明,会造成用户对处理边界的理解偏差。
This configuration embeds multiple third-party model endpoints and includes live-looking API credentials for some providers, creating a real risk that sensitive resume contents will be transmitted off-platform without clear user awareness. Because resumes commonly contain PII and career history, undisclosed or poorly governed transmission to external vendors can cause privacy, compliance, and data-handling violations.
This entry contains a real external API endpoint alongside a hardcoded Tencent-style secret key, enabling unauthorized use of the provider account and facilitating transmission of sensitive resume/JD data to a third party. Exposure of embedded credentials in a skill repository is a direct secret-management failure and can lead to billing abuse, account compromise, and privacy incidents.
tencent:
name: "腾讯"
api_key: "sk-sp-sq7Y7eo9L0vgFpuESFLq5YsQB8qumjDnwOPeciB9v3F0BSKv"
api_url: "https://api.lkeap.cloud.tencent.com/coding/anthropic/v1/messages"
model: "hunyuan-t1"
description: "腾讯 Hunyuan-T1,适合长文本分析"
This configuration enables outbound transmission to DeepSeek if api mode is used, which is security-relevant because resumes may contain sensitive personal data. Although the shown key is a placeholder rather than a live secret, the egress path still creates privacy and compliance risk if enabled without proper notice and controls.
deepseek:
name: "DeepSeek"
api_key: "YOUR_DEEPSEEK_API_KEY"
api_url: "https://api.deepseek.com/v1/chat/completions"
model: "deepseek-chat"
description: "DeepSeek-V3,开源模型,成本低"
This Moonshot endpoint similarly establishes a ready external transmission path for sensitive resume and JD content. Even with a placeholder key, the configuration makes remote processing easy to enable, which is risky in a resume-matching skill where personal data exposure is a primary concern.
moonshot:
name: "月之暗面"
api_key: "YOUR_MOONSHOT_API_KEY"
api_url: "https://api.moonshot.cn/v1/chat/completions"
model: "moonshot-v1-8k"
description: "Kimi,长上下文支持好"
This manifest/config template uses Chinese throughout comments, labels, and descriptions, which effectively forces a specific language for users interacting with the skill configuration. The policy allows locale constraints only when they are clearly documented and justified or when users are given a choice, neither of which appears here.
The configuration explicitly sends resume and JD content to third-party cloud LLM endpoints, and the same file states resumes may be sent in full with no character limit. Because resumes commonly contain sensitive personal data, this creates a real data-exposure and privacy risk if operators use external providers without consent, minimization, or data-handling safeguards. In this skill context, the risk is elevated because the core workflow involves bulk processing of personal documents.
tencent:
name: "腾讯 Hunyuan"
api_key: "YOUR_TENCENT_API_KEY"
api_url: "https://api.lkeap.cloud.tencent.com/coding/anthropic/v1/messages"
model: "hunyuan-t1"
description: "腾讯 Hunyuan-T1,适合长文本分析"
This code includes natural-language instructions, status messages, and usage guidance entirely in Chinese, such as the module docstring and printed runtime messages. Because the file does not provide any opt-in or alternative locale, it imposes a specific language on users, which matches the language/locale policy violation criteria.
Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.
API_KEY = None
API_URL = None
MODEL = None
MAX_TOKENS = None
TIMEOUT = 60
# 路径配置
The code persistently caches parsed resume and JD text as JSON files alongside source documents, but this storage behavior is not reflected in the skill description. This creates silent at-rest retention of sensitive applicant data, increasing exposure if the workstation, shared folders, backups, or downstream tools are accessed by unauthorized parties.
The network submission path sends resume content to an external API without any user-facing warning, confirmation, or contextual disclosure at runtime. In a resume-processing skill, this omission is risky because users may reasonably expect local handling of applicant data and may not realize regulated or confidential content is leaving the environment.
The code performs an outbound HTTP POST to a configurable API endpoint carrying full prompt contents, which include resume and JD text. External transmission itself is not always forbidden, but in this context it is sensitive because the payload contains personal data and the destination is configurable without visible safeguards such as allowlisting or explicit user approval.
}
try:
response = requests.post(API_URL, headers=headers, json=data, timeout=TIMEOUT)
if response.status_code == 200:
result = response.json()
if 'choices' in result:
No suspicious patterns detected.