Back to skill

Security audit

DeepRead Resume Parser

Security checks for vulnerabilities and agentic risk

Overview

This skill clearly describes a resume parser that sends selected resume files to DeepRead's API, with no evidence of hidden execution, persistence, or destructive behavior.

Install only if you are comfortable sending resume contents, including personal contact and work-history data, to DeepRead's API. Review DeepRead's privacy, retention, and BYOK handling before processing real candidate data, and inspect any optional related skills before installing them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:64
Finding

Unpinned External Skill Installations Create Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:64, SKILL.md:171, and SKILL.md:184-186
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

The Skill recommends installing externally maintained Skills without specifying immutable versions, release identifiers, or content hashes.

Code snippets (SKILL.md:64):

markdown
No key yet? `clawhub install uday390/deepread-agent-setup` and your agent fetches one via OAuth device flow.

Code snippets (SKILL.md:171):

markdown
Install: `clawhub install uday390/deepread-pii`

Code snippets (SKILL.md:184-186):

markdown
- **deepread-ocr** — general OCR + structured extraction — `clawhub install uday390/deepread-ocr`
- **deepread-form-fill** — fill application forms from parsed data — `clawhub install uday390/deepread-form-fill`
- **deepread-pii** — redact for blind screening — `clawhub install uday390/deepread-pii`

Technical Analysis

These commands resolve external Skill packages by mutable names. The project does not pin a reviewed version or content digest and does not include the referenced implementations, so their effective behavior cannot be established from the audited artifact.

The deepread-agent-setup dependency is particularly sensitive because the documentation states that it conducts an OAuth device flow and obtains an API credential. If the referenced package, publisher account, distribution channel, or dependency resolution process is compromised, a later installation could differ from the version originally intended or reviewed. It could present misleading authorization instructions, capture credentials, or issue instructions that access resources available to the agent.

The primary resume-processing workflow only requires document read access, network access to the declared API, and an existing API key. Installing additional Skills is therefore not a minimum-privilege requirement for ...[truncated 1407 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every external Skill to an immutable, reviewed version, commit identifier, or cryptographic content digest.
  2. Verify package signatures and checksums before installation, and fail closed if verification is unavailable or unsuccessful.
  3. Publish links to the exact source revisions used and subject those revisions to the same security review as the primary Skill.
  4. Make optional integrations explicitly optional and avoid automatic installation during the primary parsing workflow.
  5. Separate credential provisioning from document processing. Users should obtain and store credentials through a trusted, independently verified flow.
  6. Document the permissions, network destinations, credential access, and local file access required by each external Skill before recommending installation.
  7. Run installed dependencies with restricted filesystem and network access, exposing only the specific files and credentials required for their declared tasks.
  8. Maintain an allowlist of approved package publishers and immutable releases, with monitoring for publisher-account or dependency compromise.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The skill instructs the agent to upload entire resume files to an external API endpoint, which is an explicit exfiltration of highly sensitive personal data including contact details, employment history, and potentially other embedded PII. Even though this is the advertised function of the skill, the transmission creates real privacy, compliance, and data-handling risk if users do not fully understand that documents leave the local environment and are processed by a third party.

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

cURL

bash
curl -s -X POST https://api.deepread.tech/v1/process \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@resume.pdf" \
  -F 'schema={"type":"object","properties":{"full_name":{"type":"string"},"email":{"type":["string","null"]},"skills":{"type":"array","items":{"type":"string"}},"work_history":{"type":"array","items":{"type":"object","properties":{"company":{"type":"string"},"title":{"type":"string"}}}}}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The PII redaction feature still requires uploading the original unredacted resume to the external service, meaning the most sensitive version of the document is transmitted before protection is applied. This can mislead users into thinking the workflow is privacy-preserving when, in fact, the third party receives raw PII first.

Content

Scanner excerpt · SKILL.md (reported line 159)May include surrounding context.

For blind/anonymized first-pass screening, redact names, photos, addresses, and other PII before the resume reaches a reviewer — reducing unconscious bias and supporting fair-hiring policies:

bash
curl -X POST https://api.deepread.tech/v1/pii/redact \
  -H "X-API-Key: $DEEPREAD_API_KEY" \
  -F "file=@resume.pdf"

Static analysis

No suspicious patterns detected.