resume-manager
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted resume data from multiple external sources, which could lead to indirect prompt injection.
- Ingestion points: SKILL.md Step 2 accepts data from uploaded files (PDF, DOCX, TXT), text pastes, or external links to LinkedIn or online resumes.
- Boundary markers: Absent; the instructions do not include delimiters or specific guidance for the agent to ignore instructions embedded within the provided resume content.
- Capability inventory: The skill executes Python scripts that write to the local file system (~/.claude/resume_data.json) and generate PDF documents in the user's Downloads folder.
- Sanitization: Absent; there is no documented process for sanitizing or validating the extracted content before it is saved to the database or used in prompt generation.
Audit Metadata