Back to skill

Security audit

简历生成技能(W工作室)

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent resume generator, but it gives a local-only privacy assurance while later directing users to upload sensitive resume data to a third-party site.

Review the generated JSON before uploading it, because it may contain your contact details, location, education, work history, and other personal resume data. Install only if you are comfortable using the external aicv.weinuo.work import workflow or can keep the output local.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:27
Finding

Misleading Local-Only Privacy Claim Despite Third-Party Résumé Upload Workflow

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:27, SKILL.md:145-150, and SKILL.md:223-227
Vulnerability Type: Privacy Misrepresentation
Risk Level: Medium

Complete Relevant Snippets

English translation of SKILL.md:27:

markdown
- 🔒 All content is processed locally and will not be uploaded.

English translation of SKILL.md:143-150:

markdown
Step 5: Kelly generates the following files:
 📄 [Name]-resume.json
 📕 [Name]-resume.pdf
 📝 [Name]-resume-info.md (backup of submitted information)
↓
Step 6: Kelly prompts the user to import the file into aicv.weinuo.work

English translation of SKILL.md:223-227:

markdown
## aicv.weinuo.work Import Steps

1. Open https://aicv.weinuo.work
2. Register or sign in, then click "Import"
3. Upload the [Name]-resume.json file

Technical Analysis

The skill makes an unconditional representation that all content is processed locally and will not be uploaded. Its prescribed workflow subsequently instructs the user to register with an external service and upload the generated résumé JSON.

The uploaded file is designed to contain personally identifiable and professional information, including the user's real name, email address, telephone number, location, employment history, education history, personal summary, and potentially website, certification, language, and project information. The version history identifies the external service as a platform operated by the skill publisher.

Local file generation is not itself an external disclosure, but uploading the generated JSON to the specified website is. The privacy assurance therefore fails to distinguish between the local generation phase and the optional or recommended third-party import phase. This can prevent users from giving informed consent before transferring sensitive information.

No evidence was found that the skill uploads data automatically. Exploitation depends on the user following the documented upload instruct ...[truncated 1472 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the unconditional local-only statement with a phase-specific disclosure, such as: “Résumé generation is performed locally. If you choose to import the generated JSON into aicv.weinuo.work, the résumé data will be uploaded to that external service.”
  2. Make third-party upload explicitly optional and request informed confirmation immediately before presenting upload instructions.
  3. Clearly enumerate the data included in the uploaded JSON, including name, email, telephone number, location, employment history, and education history.
  4. Link to the external service's privacy policy and document its operator, processing purpose, retention period, deletion procedure, security controls, and any onward sharing.
  5. Provide a fully local workflow for generating and viewing the résumé without requiring registration or external upload.
  6. Apply data minimization by allowing users to omit unnecessary contact or location details before export.
  7. Warn users to review the generated JSON before uploading it and provide a redacted export option.
  8. Keep the privacy statement and workflow synchronized through documentation tests or release-review checks so future destination changes cannot reintroduce contradictory claims.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description and all user-facing instructions are presented exclusively in Chinese, and the workflow assumes the assistant will guide the user in that language. This creates a natural-language locale constraint without any opt-in or alternative language option, which matches the policy-violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill claims resume content is handled locally, but later instructs the user to import the generated JSON into an external site to complete PDF generation. This is dangerous because users may disclose highly sensitive personal data under a misleading expectation of local-only processing, increasing privacy and data-sharing risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to package all user-provided resume details into a backup markdown file, which naturally aggregates sensitive personal information such as name, contact details, education, and employment history. Consolidating and retaining this data increases exposure risk through accidental disclosure, over-retention, or unintended reuse beyond the immediate resume-generation task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file includes a resume template that fixes the page locale to "zh-CN", and the surrounding headings and field labels are entirely Chinese. Under the policy rule, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is explicitly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The schema example sets "locale": "zh-CN" as the default locale in the natural-language documentation. Because this markdown file does not indicate that users may choose another locale or that the locale is only an example, it imposes a specific language/locale setting without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.