Back to skill

Security audit

Resume Styles Kit(简历风格生成)

Security checks for vulnerabilities and agentic risk

Overview

The skill appears aimed at resume PDF generation, but it gives conflicting instructions about whether to use or anonymize sensitive resume details.

Before installing, decide whether this skill should create anonymized sample resumes or real applications. If using real resumes, only provide personal details, company names, project details, education, and metrics you intentionally want included, and keep generated HTML/PDF files local unless you explicitly approve any cloud or database workflow.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description broadly says the skill can 'generate or optimize resumes' and 'restore skills structure and batch convert to PDF' but does not define specific trigger phrases, activation boundaries, or exclusion conditions. In a manifest file, this ambiguity can cause unintended invocation for general resume-help requests rather than a narrowly scoped formatting task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructions and user-facing content are entirely written in Chinese and do not state that the user may choose another language or locale. This creates a natural-language policy risk because the skill appears to impose a specific language by default without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill gives conflicting privacy and data-handling instructions: it first mandates de-identification and forbids real personal, educational, company, project, and quantitative data, then later instructs the agent to build resume sections using the candidate's real information and education background. This inconsistency can cause an agent to disclose sensitive personal data into generated artifacts or intermediate files because the operative rule is unclear.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill simultaneously requires strict adherence to real candidate experience and real quantified results while also prohibiting quantitative data and specific company/project details. An agent following both directions may mishandle sensitive resume content, either leaking private metrics/details or unpredictably transforming user data in ways that violate privacy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.