resume-tailoring

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external URLs, including job descriptions and LinkedIn profiles, which represents an attack surface for indirect prompt injection. \n
  • Ingestion points: Fetches external content via URLs and web searches in Phase 1 (Research Phase). \n
  • Boundary markers: The skill lacks explicit instructions to delimit or ignore instructions embedded within the fetched external data. \n
  • Capability inventory: The skill can list and read files in the local resume directory, write documents via sub-skills, and perform web operations. \n
  • Sanitization: No sanitization or validation logic for the fetched content is specified in the instructions. \n- [EXTERNAL_DOWNLOADS]: The skill fetches data from the web (e.g., LinkedIn and company blogs) to build a success profile. While these are remote operations, they are consistent with the skill's stated purpose of role research.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:34 AM
Security Audit — agent-trust-hub — resume-tailoring