resume-optimizer

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of Markdown documentation and JSON metadata. No executable scripts (.sh, .py, .js) or system commands are present in the analyzed files.
  • [SAFE]: No network operations, data exfiltration patterns, or external downloads were identified.
  • [SAFE]: No obfuscation or hidden content was detected. High entropy warnings in the provided metadata were correctly identified as false positives caused by standard Chinese Unicode characters.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user-supplied resumes and job descriptions (identified in SKILL.md and prompt_templates in skill-report.json). While this data represents an external ingestion point for potential indirect prompt injection, the skill lacks any capabilities (such as file system writes, network access, or command execution) to exploit such an injection. Boundary markers and sanitization are absent, but the lack of functional capabilities renders this risk negligible.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 02:53 AM
Security Audit — agent-trust-hub — resume-optimizer