Back to skill

Security audit

Resume Optimizer

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent resume-building helper, but its PDF script can silently install an unpinned package into the Python environment at runtime.

Review before installing. The resume workflows themselves are purpose-aligned, but run PDF generation only in a disposable virtual environment or container, or preinstall a pinned reportlab dependency and remove the auto-install path. Avoid including unnecessary personal details in resumes and be aware that generated filenames may contain your name.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/generate_resume_pdf.py:17
Finding

Unpinned Dependency Installation at Runtime

Content
View full analysis

Vulnerability Details

File Location: scripts/generate_resume_pdf.py, lines 17–27
Vulnerability Type: Unpinned runtime dependency installation
Risk Level: Medium

Complete Code Snippet

python
try:
    from reportlab.lib.pagesizes import letter
    from reportlab.lib.units import inch
    from reportlab.lib.styles import getSampleStyleSheet, ParagraphStyle
    from reportlab.lib.enums import TA_LEFT, TA_CENTER
    from reportlab.platypus import SimpleDocTemplate, Paragraph, Spacer, HRFlowable
    from reportlab.lib.colors import HexColor
except ImportError:
    print("Installing reportlab...")
    import subprocess
    subprocess.check_call(['pip', 'install', 'reportlab', '--break-system-packages', '-q'])
    from reportlab.lib.pagesizes import letter
    from reportlab.lib.units import inch

Technical Analysis

When reportlab cannot be imported, the script automatically invokes pip to download and install the package. The dependency has no version constraint, cryptographic hash, lockfile, or explicitly trusted package index. Consequently, the exact code installed and executed can change after the Skill has been audited.

Python package installation may execute package-controlled build or installation logic. A compromised package release, dependency, configured package index, package mirror, or network path could therefore cause arbitrary code execution under the privileges of the user running this script.

The --break-system-packages option weakens environment isolation by permitting changes to a system-managed Python installation. This can modify shared dependencies, destabilize other applications, and broaden the impact beyond the resume-generation process.

Attack Path

  1. A user or agent runs the PDF generator in an environment where reportlab is unavailable or its import fails.
  2. The ImportError handler invokes the environment-resolved pip executable.
  3. pip contacts its configured package index or mirror ...[truncated 1236 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic package installation from application runtime. If reportlab is absent, terminate with a clear error explaining how to prepare the environment.

  2. Declare reportlab in a dependency manifest and pin it to a reviewed version.

  3. Use a lockfile or hash-verified requirements file, such as:

    text
    reportlab==REVIEWED_VERSION --hash=sha256:VERIFIED_PACKAGE_HASH
    
  4. Install dependencies during a controlled build or deployment phase rather than while processing user requests.

  5. Use a dedicated virtual environment or container instead of --break-system-packages.

  6. Configure an approved package index or internal mirror and enforce TLS certificate validation.

  7. Run dependency vulnerability and provenance checks during CI.

  8. Execute PDF generation under a least-privileged account with restricted filesystem and network access.

  9. Replace the current handler with fail-closed behavior:

    python
    try:
        from reportlab.lib.pagesizes import letter
        # Other required imports
    except ImportError as exc:
        raise SystemExit(
            "Missing required dependency: reportlab. "
            "Install the pinned project dependencies before running this script."
        ) from exc
    
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code’s actual function is narrowly limited to PDF rendering of already-prepared resume data. It supports multiple resume formats and outputs a PDF, which partially aligns with the declared PDF export capability. However, the broader declared description says the skill can build resumes, customize them for specific roles, analyze them, and provide recommendations. None of those capabilities are implemented in this code chunk. The code accepts JSON input, formats sections, and writes a PDF; it contains no logic for content generation, tailoring, scoring, ATS analysis, or recommendation generation. Therefore the description materially overstates the skill’s implemented behavior.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/ats-optimization.md (reported line 244)May include surrounding context.

md
- Note technical terms
   - Identify required vs. preferred

2. **Update Skills Section**
   - Lead with most relevant skills
   - Use exact phrasing from job description
   - Include both acronyms and full names

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill instructs the agent to read local reference files and invoke a shell command to generate PDFs, but it does not declare any explicit tool scope or permissions. This creates an authorization and auditability gap: an agent may use broader-than-necessary file and shell capabilities, increasing the chance of unintended file access or command execution if downstream inputs are mishandled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This skill handles highly sensitive personal data including employment history, education, contact details, and potentially job descriptions, then writes exported files to disk for download. The documentation lacks any warning, minimization guidance, or handling constraints for personal data, which increases the risk of oversharing, insecure retention, or accidental exposure through generated files and output locations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This checklist guides resume analysis and offers to implement changes, which inherently involves processing highly sensitive personal data such as names, email addresses, phone numbers, employment history, education, and possibly location or portfolio links. The file contains no privacy, minimization, or redaction guidance, increasing the risk that users or downstream systems will expose, retain, or mishandle personal information during analysis and rewriting.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Installing dependencies on the fly is outside the normal scope of a resume PDF generator and causes side effects on the executing machine. This is dangerous because it implicitly trusts external package retrieval at runtime and may break environment integrity, especially with the use of --break-system-packages.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script automatically performs a pip install without warning or confirmation, which means a user requesting PDF generation may unknowingly trigger network access and environment modification. This is particularly risky in shared, locked-down, or production systems, and the --break-system-packages flag increases the chance of damaging the Python environment.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
97% confidence
Finding

The script executes pip as a subprocess at runtime to modify the host environment and install a package. Even though the package name is hardcoded, this creates an unnecessary execution and supply-chain risk surface, can alter system state without consent, and may install code from external package indexes during normal document generation.

Content

Scanner excerpt · scripts/generate_resume_pdf.py (reported line 21)May include surrounding context.

python
except ImportError:
    print("Installing reportlab...")
    import subprocess
    subprocess.check_call(['pip', 'install', 'reportlab', '--break-system-packages', '-q'])
    from reportlab.lib.pagesizes import letter
    from reportlab.lib.units import inch
    from reportlab.lib.styles import getSampleStyleSheet, ParagraphStyle

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example invocation "Help me build a resume" is a broad, natural phrase that could overlap with ordinary conversation. The document does not provide explicit trigger boundaries, exclusions, or negative examples to clarify when this skill should or should not activate.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.