weekly-retro

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No security concerns identified. The skill's behavior is consistent with its stated purpose of managing job search progress.- [PROMPT_INJECTION]: Surface for indirect prompt injection via ingestion of user-controlled YAML files.
  • Ingestion points: Local files such as search/pipeline/open-roles.yaml and search/pipeline/applications.yaml.
  • Boundary markers: Absent; instructions do not specify delimiters to separate data from instructions.
  • Capability inventory: File system modifications (Write, Edit), shell access (Bash), and blackboard channel tools.
  • Sanitization: Absent; the agent processes external file content without validation or escaping.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 05:36 AM
Security Audit — agent-trust-hub — weekly-retro