Back to skill

Security audit

Ai-Interview-Skill

Security checks for vulnerabilities and agentic risk

Overview

This interview-coaching skill is not malicious, but it automatically stores detailed local records of users' interview answers and uses unsafe user-controlled filenames.

Review this skill before installing if you may discuss confidential interview questions, employer code, personal history, or proprietary designs. It should be changed to ask before saving, store summaries by default, validate profile names/domains, avoid shell interpolation, and provide a clear way to delete saved profiles and sessions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
skill.md:117
Finding

Unsanitized User-Controlled Values in File Paths and Shell Command

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill automatically saves complete session logs with exact answers, evaluations, timestamps, and improvement plans, but provides no clear up-front warning or consent flow. Because users may paste proprietary code, employer-specific interview questions, or personal details into answers, automatic transcript retention materially increases confidentiality and privacy risk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

Persistent profile storage is a real security-relevant capability because it writes user-linked data to ~/.claude/ai-interview/ for future reuse. In context, this is not inherently malicious, but it is more access than an interview coach strictly needs and becomes risky without consent, minimization, and isolation.

Content

Scanner excerpt · skill.md (reported line 115)May include surrounding context.

md
| System Design | Staff Engineer | Architecture, scalability, trade-offs |
| Algorithms/DS | Senior SWE | Problem solving, complexity, optimization |

### Step 1: Load or Create User Profile

User ability profiles are stored in: `~/.claude/ai-interview/`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill declares that user ability profiles will be stored on disk under ~/.claude/ai-interview/ but does not clearly warn users in the skill description that their data will be persisted. This creates a privacy and transparency failure: users may disclose personal identifiers or performance data without realizing it will be retained across sessions.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The profile design encourages long-term accumulation of user performance history and topic-level abilities without minimization, expiry, or sensitivity checks. Over time, this builds a behavioral dossier that exceeds what is necessary for a basic interview practice interaction and can reveal learning weaknesses or other personal attributes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to persist full interview notebooks containing exact user answers, detailed feedback, scores, and timestamps to disk. For an interview-coaching skill, this creates unnecessary retention of potentially sensitive user-provided content and expands the blast radius if local files are later read by other tools, skills, or users on the same system.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The requirement to store and later reproduce users' exact answers in persistent logs creates a data disclosure risk beyond simple scoring or coaching. Exact free-form answers can contain secrets, personal data, copyrighted material, or sensitive work information, and preserving them verbatim makes accidental exposure more damaging.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

The session-log persistence capability is real and materially expands the skill's authority by creating durable records of conversations on disk. In an interview coach, that context makes the finding more dangerous because users are likely to share substantial free-form technical content, yet the skill offers no justification strong enough to require automatic archival of full sessions.

Content

Scanner excerpt · skill.md (reported line 313)May include surrounding context.

md
**2. Save interview session notebook** for future review:

Create a detailed session log at: `~/.claude/ai-interview/sessions/{username}_{domain}_{YYYYMMDD}_{HHMMSS}.md`

Session notebook format:

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill includes shell-style directory creation instructions (mkdir -p sessions) even though its stated purpose is interview coaching. This introduces filesystem side effects and nudges the agent toward command-like behavior unrelated to answering interview questions, which can become risky in environments where tool execution is available.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.