review-software-engineer-cv

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill is designed to fetch resume formatting and technical role guidance from established, well-known educational institutions and industry blogs, including Yale University, Princeton University, and O*NET Online. These external references are restricted to read-only intake and do not involve script execution or package installation.
  • [DATA_EXFILTRATION]: The instructions across multiple files (SKILL.md, references/cv-review-contract.md, subagents/source-intake-analyst.md) include robust privacy constraints that strictly prohibit uploading or pasting user CVs, private job text, or applicant context into external resume scanners, forms, or third-party analysis tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted user input in the form of CVs and job descriptions. It mitigates potential instruction injection by enforcing a 'CV Review Contract' which requires all edits to be grounded in source evidence and labeled with specific match-strength and truthfulness markers. Mandatory Evidence Chain: 1. Ingestion points: CV and JOB_POSTING inputs in source-intake-analyst.md. 2. Boundary markers: Explicit integrity rules and match-strength labels in references/cv-review-contract.md. 3. Capability inventory: Orchestrated subagent review and read-only web fetching. 4. Sanitization: A 'Sensitive Candidate Claim Resolution' process to weaken, exclude, or verify unsupported claims.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 07:21 PM
Security Audit — agent-trust-hub — review-software-engineer-cv