rendercv-resume-handoff

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill functions as a coordination layer for transforming career data into deterministic resume artifacts using RenderCV.
  • [EXTERNAL_DOWNLOADS]: References the external repository rendercv/rendercv-skill. This is a legitimate integration with a well-known open-source resume generation framework.
  • [COMMAND_EXECUTION]: Provides setup instructions using the npx skills add command to install necessary external dependencies. These commands are transparent and target reputable project identifiers.
  • [PROMPT_INJECTION]: The skill identifies a surface for processing untrusted resume content.
  • Ingestion points: Resume data from the Career Positioning OS.
  • Boundary markers: Instructions to produce "public-safe" bullet text and section content.
  • Capability inventory: Hand-off to the RenderCV skill for YAML generation and rendering.
  • Sanitization: Guidance includes strict preservation of factual claims and metrics without invention of data.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 10:58 AM
Security Audit — agent-trust-hub — rendercv-resume-handoff