boss-resume-downloader
Warn
Audited by Snyk on May 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill directly invokes the external BOSS/Zhipin service via the boss CLI (see run_boss calls like "hr applications", "hr resume", and "hr candidates" in scripts/sync_boss_resumes.py and the SKILL.md) to fetch user-generated candidate/application/resume data which the agent parses and uses to decide downloads and next actions, exposing it to untrusted third-party content that could inject instructions.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata