Back to skill

Security audit

小红书面经采集与回答

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for interview research, but its Windows setup installs mutable third-party code and disables OCR model-source validation, so it needs careful review before installation.

Install only if you are comfortable with a Windows setup that downloads and runs OpenCLI, Python/PaddleOCR dependencies, Chrome components, and OCR models in a user-local runtime. Keep generated archives local unless you have reviewed and redacted author names, signed links, screenshots, OCR text, and any personal resume facts. For safer deployment, ask the publisher to pin dependency versions and hashes, remove disabled OCR model-source validation, and document retention/deletion controls.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Error
Location
scripts/deployment/windows/install.ps1:157
Finding

Unpinned Third-Party Dependencies Permit Mutable Code Execution

Content
View full analysis
=3.0,<4' -i 'https://www.paddlepaddle.org.cn/packages/stable/cpu/' if ($LASTEXITCODE -ne 0) { throw 'Could not install the PaddlePaddle CPU runtime.' } & $venvPython -m pip install paddleocr pillow python-docx markdown if ($LASTEXITCODE -ne 0) { throw 'Could not install PaddleOCR and document export dependencies.' } } ``` ### Technical Analysis The installer retrieves and installs executable third-party components without pinning them to immutable versions or verified package hashes: - OpenCLI uses the mutable `@latest` tag. - PaddlePaddle permits any release in the broad `>=3.0,<4` range. - PaddleOCR, Pillow, python-docx, and Markdown have no version constraints. - pip itself is upgraded to whichever ...[truncated 2549 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/deployment/windows/install.ps1:18
Finding

Remote OCR Model Provenance Validation Is Explicitly Disabled

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (35)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 17)May include surrounding context.

text
*.log

# Secrets and local configuration
.env
.env.*
deployment.json
state.json

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/byteintern-user-growth-product-manager/面经汇总.html (reported line 735)May include surrounding context.

html
如果产品与分析类二选一你会怎么选,为什么
反思:没过的原因大概率是无产品经验+竞争对手履历更丰富,其次二面部分开放性问题的回答覆盖不够
#互联网大厂 #字节跳动 #互联网大厂实习 #tiktok #产品经理 #面经</p>
<!-- OCR:START -->
<h4 id="图片与-ocr">图片与 OCR</h4>
<h5 id="p01-i01">P01-I01</h5>
<figure>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/byteintern-user-growth-product-manager/面经汇总.html (reported line 834)May include surrounding context.

html
<blockquote>
<p>OCR 由机器生成,可能存在识别错误,请以原图为准。</p>
</blockquote>
<!-- OCR:END -->
</section>
<p><a id="P03" class="post-anchor"></a></p>
<section id="p03-fdu研0字节增长产品面经long-time-no-see"

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/byteintern-user-growth-product-manager/面经汇总.html (reported line 834)May include surrounding context.

html
<blockquote>
<p>OCR 由机器生成,可能存在识别错误,请以原图为准。</p>
</blockquote>
<!-- OCR:END -->
</section>
<p><a id="P03" class="post-anchor"></a></p>
<section id="p03-fdu研0字节增长产品面经long-time-no-see"

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/byteintern-user-growth-product-manager/面经汇总.html (reported line 903)May include surrounding context.

html
<blockquote>
<p>OCR 由机器生成,可能存在识别错误,请以原图为准。</p>
</blockquote>
<!-- OCR:END -->
</section>
<p><a id="P04" class="post-anchor"></a></p>
<section id="p04-从tiktok-用户增长策略看如何准备用增面试"

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/byteintern-user-growth-product-manager/面经汇总.html (reported line 1069)May include surrounding context.

html
<blockquote>
<p>OCR 由机器生成,可能存在识别错误,请以原图为准。</p>
</blockquote>
<!-- OCR:END -->
</section>
<p><a id="P05" class="post-anchor"></a></p>
<section id="p05-抖音增长策略产品实习面经分享" class="post-card">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/byteintern-user-growth-product-manager/面经汇总.html (reported line 1120)May include surrounding context.

html
<blockquote>
<p>OCR 由机器生成,可能存在识别错误,请以原图为准。</p>
</blockquote>
<!-- OCR:END -->
</section>
<p><a id="P06" class="post-anchor"></a></p>
<section id="p06-字节跳动抖音用户增长部门ai产品经理面经"

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/byteintern-user-growth-product-manager/面经汇总.html (reported line 1204)May include surrounding context.

html
<blockquote>
<p>OCR 由机器生成,可能存在识别错误,请以原图为准。</p>
</blockquote>
<!-- OCR:END -->
</section>
<p><a id="P07" class="post-anchor"></a></p>
<section id="p07-拿下ssp-ofr用增pm一面面经" class="post-card">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/byteintern-user-growth-product-manager/面经汇总.html (reported line 1204)May include surrounding context.

html
<blockquote>
<p>OCR 由机器生成,可能存在识别错误,请以原图为准。</p>
</blockquote>
<!-- OCR:END -->
</section>
<p><a id="P07" class="post-anchor"></a></p>
<section id="p07-拿下ssp-ofr用增pm一面面经" class="post-card">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/byteintern-user-growth-product-manager/面经汇总.html (reported line 1372)May include surrounding context.

html
<blockquote>
<p>OCR 由机器生成,可能存在识别错误,请以原图为准。</p>
</blockquote>
<!-- OCR:END -->
</section>
<p><a id="P08" class="post-anchor"></a></p>
<section id="p08-面经丨字节用增策略产品岗丨归纳总结" class="post-card">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/byteintern-user-growth-product-manager/面经汇总.html (reported line 1588)May include surrounding context.

html
<blockquote>
<p>OCR 由机器生成,可能存在识别错误,请以原图为准。</p>
</blockquote>
<!-- OCR:END -->
</section>
<p><a id="P09" class="post-anchor"></a></p>
<section id="p09-字节跳动交易产品经理一面面经1h拷打" class="post-card">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/byteintern-user-growth-product-manager/面经汇总.html (reported line 1588)May include surrounding context.

html
<blockquote>
<p>OCR 由机器生成,可能存在识别错误,请以原图为准。</p>
</blockquote>
<!-- OCR:END -->
</section>
<p><a id="P09" class="post-anchor"></a></p>
<section id="p09-字节跳动交易产品经理一面面经1h拷打" class="post-card">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/byteintern-user-growth-product-manager/面经汇总.html (reported line 1646)May include surrounding context.

html
<blockquote>
<p>OCR 由机器生成,可能存在识别错误,请以原图为准。</p>
</blockquote>
<!-- OCR:END -->
</section>
<p><a id="P10" class="post-anchor"></a></p>
<section id="p10-字节产品-国际支付面经" class="post-card">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · examples/byteintern-user-growth-product-manager/面经汇总.html (reported line 1720)May include surrounding context.

html
<blockquote>
<p>OCR 由机器生成,可能存在识别错误,请以原图为准。</p>
</blockquote>
<!-- OCR:END -->
</section>
<p><a id="P11" class="post-anchor"></a></p>
<div class="post-card">

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs the agent to perform filesystem writes, read local files, invoke PowerShell/Python scripts, and access the network, but it does not declare an explicit tool scope such as allowed-tools or permissions. That mismatch weakens least-privilege controls and can let the runtime or reviewer underestimate the skill's real capabilities, increasing the chance of unintended file access, execution, or network activity when handling adversarial inputs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The default prompt triggers broad collection and generation behavior from only a JD, without clearly constraining scope, consent boundaries, or when the personalization step should occur. In a skill that gathers external content and may later combine it with user resume materials, vague invocation criteria can cause over-collection, unintended processing of personal data, or use outside the intended interview-preparation context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template headings and instructional content are entirely in Chinese, which imposes a specific language/locale on generated output. The file does not indicate that this is optional, user-selected, or justified as a region-specific skill, so it appears to violate the language/locale policy requirement.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The page is presented as a summary for "用户增长产品经理" and the overview labels the target role accordingly, but included posts cover transaction product and international payment cashier/product roles as well. That indicates the skill's behavior, at least in this example output, is broader than the role-specific collection and screening implied by the document framing and manifest description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest says the skill is for non-technical roles such as product, operations, sales, design, and similar interviews, and explicitly says not to use it for coding interviews. This generated HTML includes a full entry for an "AI产品经理" interview with discussion of models, agents, prompts, and AI project implementation, which goes beyond the stated non-technical-role scope and shows the skill output can include more technical interview material than advertised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow explicitly directs persistent collection of scraped post content, images, author nicknames, note IDs, and signed URLs, but provides no user warning, minimization guidance, retention limit, or deletion policy. Even though the source data is public, aggregating and archiving it locally increases privacy, compliance, and secondary-disclosure risk, especially because signed URLs and images may preserve access paths and personally identifying context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file explicitly requires storing public author nicknames and complete signed source URLs in generated artifacts. Even if the posts are public, preserving signed URLs and identity-linked metadata in local archives increases traceability, can expose access parameters or session-bound link data, and creates unnecessary privacy risk when documents are shared onward without notice or minimization.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions require embedding all original post images and OCR text into Markdown, Word, and HTML outputs. Interview-experience screenshots often contain personal data, usernames, profile elements, recruiter names, phone numbers, chat fragments, or other sensitive text; OCR makes that content searchable and much easier to redistribute at scale, materially increasing exposure risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The installer automatically downloads and installs Node.js, OpenCLI, Python, PaddleOCR dependencies, and Chrome, and also creates runtime state on disk when not run with -CheckOnly. Although some integrity checks are present for Node, Python, and Chrome, these are still significant network and system-modifying actions without an explicit interactive consent step, which is risky for an agent skill because execution may surprise users and enlarge the supply-chain attack surface.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file launches the resolved Python interpreter against a caller-supplied script path and arguments, which is a subprocess-style execution with potentially broad effects. The file contains no confirmation prompt, warning comment/docstring, or user-facing logging near the execution point to disclose that it will run arbitrary code.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The validator hard-codes required metadata labels in Chinese (e.g. 原帖链接, 发布时间, note ID formatting) and later requires Chinese-named files and directories, which effectively forces a specific language/locale for valid input. The file does not indicate that this is an explicitly region-specific tool or offer any opt-in or alternative locale handling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.