Back to skill

Security audit

Interview Prep

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but its documented curl workflow creates a real review concern because free-form job data could be unsafely interpolated into shell commands.

Install only if you trust the local service on 127.0.0.1:8010 and the agent environment uses safe structured HTTP or JSON serialization instead of direct shell-string substitution. Avoid sending confidential job descriptions, employer information, or internal company material unless the localhost service's handling and retention are acceptable.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:34
Finding

Shell Command Injection Through Unsafe Interpolation in Curl Templates

Content
View full analysis
","use_company_intel":true,"question_count":8}'` - By custom input: - `curl -sS -X POST "http://127.0.0.1:8010/api/interview/prep" -H "Content-Type: application/json" -d '{"company":"MiniAgent","role_title":"AI Agent Intern","jd_text":"Need Python, LangGraph, RAG","use_company_intel":true,"question_count":8}'` ``` ### Technical Analysis The Skill directs an Agent to invoke `curl` through an execution tool while embedding values such as `job_id`, `company`, `role_title`, and `jd_text` inside a single-quoted shell argument. These values originate from user input. If the Agent implements the templates through direct string substitution, a supplied single quote can terminate the JSON argument. The remaining input can then introduce shell metacharacters and an arbitrary command. JSON quoting alone does not provide shell escaping because the shell parses the command before `curl` receives its arguments. The vulnerable pattern is conceptually equivalent to: ```sh curl ... -d '{"job_id":"USER_INPUT", ...}' ``` A malicious value containing a sequence such as: ```text '; attacker_command; # ``` could transform the generated command into multiple shell commands. The issue also applies to free-form JD text, which is particularly likely to contain punctuation and is not constrained or safely serialized by the documented workflow. ### Attack Path 1. An attacker provides a crafted `job_id`, company name, role title, or JD text containing a single quote followed by shell syntax. 2. The Agent follows the documented `exec tool + curl` workflow. 3. The Agent directly substitutes ...[truncated 1401 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger section lists only Chinese activation phrases, which imposes a specific language expectation in the skill's natural-language interface. There is no indication that users may invoke the skill in other languages or that the skill is intentionally limited to a Chinese-language context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill instructs the agent to send potentially sensitive job-seeking data, including company name, role title, JD text, and optionally company intelligence flags, to a local HTTP service via curl. Even though the destination is localhost, this is still an external process and network boundary where sensitive user or enterprise data can be transmitted without any documented validation, minimization, authentication, or user-consent controls.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
## Command templates (exec tool + curl)

- By job id:
  - `curl -sS -X POST "http://127.0.0.1:8010/api/interview/prep" -H "Content-Type: application/json" -d '{"job_id":"<job_id>","use_company_intel":true,"question_count":8}'`
- By custom input:
  - `curl -sS -X POST "http://127.0.0.1:8010/api/interview/prep" -H "Content-Type: application/json" -d '{"company":"MiniAgent","role_title":"AI Agent Intern","jd_text":"Need Python, LangGraph, RAG","use_company_intel":true,"question_count":8}'`

Static analysis

No suspicious patterns detected.