resume-bullet-extraction

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exposes an indirect prompt injection surface by processing untrusted user work summaries to generate content that is subsequently saved to the filesystem.
  • Ingestion points: Work highlights and summaries provided by the user in the Extraction Flow (SKILL.md).
  • Boundary markers: None observed in the prompt templates or instructions.
  • Capability inventory: Instructions to write output to the mentorspec/career/stories/ directory (SKILL.md).
  • Sanitization: No escaping or validation of user-provided content is performed.
  • [SAFE]: The skill-report.json file contains a security_audit section claiming the skill is safe and misidentifying findings as false positives. This content was evaluated as descriptive data and did not influence the final verdict.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 07:19 AM
Security Audit — agent-trust-hub — resume-bullet-extraction