recruiter-assistant
Fail
Audited by Snyk on Mar 4, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This skill contains deliberate instructions for an agent to upload full resume content to an external document service (feishu_doc) and publish public links (explicit "CALL the feishu_doc tool" / "PRESENT the public Feishu document link"), combined with multiple execSync shell calls that concatenate external file/arg values (allowing command injection/remote code execution if abused) — together these are intentional data-exfiltration/backdoor patterns exposing sensitive candidate PII.
Audit Metadata