upwork-profile-optimizer

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill instructs the agent to read a profile data file named upwork-profile.md from the local working directory or the ~/.claude/ directory. This access is specific to the skill's stated purpose of optimizing an existing freelancer profile and does not target sensitive system or credential files.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data in the form of freelancer profile text provided by the user or read from a local file.
  • Ingestion points: User-pasted profile content and the upwork-profile.md file (SKILL.md).
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions for the processed data.
  • Capability inventory: The skill utilizes file reading capabilities to retrieve profile context.
  • Sanitization: No specific sanitization or filtering of the ingested profile content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 01:21 PM
Security Audit — agent-trust-hub — upwork-profile-optimizer