upwork-proposal-writer

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes user-provided Upwork job posts which are untrusted external inputs. This creates a surface for indirect prompt injection where a malicious job description could attempt to manipulate the agent's behavior. The risk is mitigated as the skill's capabilities are limited to reading a local profile file and generating text drafts for user review.
  • [NO_CODE]: The skill is comprised entirely of natural language instructions and lacks any executable scripts, binary files, or remote code dependencies. This prevents common attack vectors such as unauthorized command execution, remote code execution, or persistence mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:17 PM
Security Audit — agent-trust-hub — upwork-proposal-writer