rendercv-resume-handoff
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill functions as a coordination layer for transforming career data into deterministic resume artifacts using RenderCV.
- [EXTERNAL_DOWNLOADS]: References the external repository rendercv/rendercv-skill. This is a legitimate integration with a well-known open-source resume generation framework.
- [COMMAND_EXECUTION]: Provides setup instructions using the npx skills add command to install necessary external dependencies. These commands are transparent and target reputable project identifiers.
- [PROMPT_INJECTION]: The skill identifies a surface for processing untrusted resume content.
- Ingestion points: Resume data from the Career Positioning OS.
- Boundary markers: Instructions to produce "public-safe" bullet text and section content.
- Capability inventory: Hand-off to the RenderCV skill for YAML generation and rendering.
- Sanitization: Guidance includes strict preservation of factual claims and metrics without invention of data.
Audit Metadata