Back to skill

Security audit

General Talent Grader

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a hiring-assessment helper, but it should be reviewed because it handles sensitive candidate data with broad automatic triggers and has scoring/tooling inconsistencies that could affect hiring decisions.

Install only if you are comfortable using it for sensitive hiring material after setting your own controls: get explicit user intent before analysis, redact unnecessary personal identifiers, avoid retaining candidate files, and treat scores as heuristic review aids rather than automated hiring decisions. Verify or replace the mismatched validator before relying on numeric levels.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill makes strong claims about performing resume auditing, quantitative deception detection, role-adaptive scoring, and interview-question generation, but the analyzed behavior reportedly does not implement those capabilities. This mismatch can mislead users into trusting unsupported assessments, causing unsafe hiring decisions or overcollection of sensitive candidate data under false pretenses.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README instructs users to process resumes and interview records, which commonly contain sensitive personal data, but provides no privacy, minimization, retention, or redaction guidance. In a talent-grading skill, this omission increases the risk of unnecessary collection, unsafe sharing, or improper downstream handling of candidate PII and confidential employment information.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are very broad and can activate on common resume or interview-related requests without clear user consent or scope boundaries. In a hiring context, this can lead to unintended processing of sensitive personal data and unsolicited evaluative outputs that users did not explicitly request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Automatic triggering on uploaded resumes or interview transcripts is risky because those files contain highly sensitive personal and employment information, and the rule does not require explicit opt-in. This increases the chance of unintended analysis, privacy intrusion, or processing beyond the user's actual purpose for upload.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is entirely written in Chinese and includes no indication that the user can choose another language or that Chinese is required for a specific regional or compliance reason. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file presents all instructions, criteria, and examples exclusively in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, a skill that imposes a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The checklist is entirely in Chinese and mandates fixed labels and workflow requirements without any language choice or opt-in. In a multi-language agent environment, this can cause the model or operator to misinterpret critical safety and grading instructions, leading to incorrect execution, missed checks, or inconsistent outputs; in hiring contexts, that also raises fairness and usability concerns.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The checklist explicitly says to run these steps when executing 'ai-talent-grader', but the manifested skill is 'general-talent-grader'. This mismatch can cause the agent to apply the wrong procedure, skip required checks, or mix controls from another skill, which undermines reliability and can create a path for prompt confusion or policy bypass if similarly named skills differ in behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document is written entirely in Chinese and presents mandatory rules ('硬规则') for the skill's operation without any indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill guidance is written in Chinese and presents all prompts, labels, and instructions exclusively in that language. There is no indication that users may choose another language or that the Chinese-only constraint is justified by a documented region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill file is written in Chinese and provides mandatory instructions such as '所有实例必须按本模板提取信号' without offering any language choice or stating that the skill is intended only for Chinese-speaking users. This creates a natural-language policy concern because it effectively enforces a specific language for all users of the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This Python file contains user-facing natural language entirely in Chinese in the module docstring and later CLI output/help text, but provides no opt-in, locale selection, or justification that the tool is region-specific. That creates a language/locale policy issue under the rule for natural-language policy violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command description, argument help text, error messages, and validation report are all user-facing strings in Chinese only. Because the file does not offer a language choice or explain a required locale scope, this is a clear natural-language locale-policy concern rather than a code-security issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file presents the skill primarily in Chinese and includes an English “Use when user asks…” directive, but nowhere states that the user may choose output language or locale. This can amount to a language-policy issue if the skill defaults communication style or analysis language without explicit opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file is entirely written in Chinese and does not state that the language choice is optional, user-selected, or limited to a Chinese-speaking audience. Under the policy rule for language or locale constraints, this can be a natural-language policy violation because it imposes a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.