cover-letter

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates entirely within the local environment using the provided 'uv' wrapper to execute its own Python scripts. It does not attempt to download external code or packages at runtime.
  • [SAFE]: All inputs, including LaTeX manuscripts and cover letter drafts, are explicitly treated as untrusted data. The instructions include robust safety boundaries directing the agent to ignore any potential prompt injections embedded in the source files.
  • [SAFE]: Data processing is handled through deterministic regex-based parsers and text extraction utilities. These scripts strip LaTeX comments and markup before analysis, preventing hidden instructions or malicious payloads from being processed as commands.
  • [SAFE]: No network exfiltration or sensitive data access patterns were found. The skill explicitly limits its scope to the bundled templates and denies online queries unless authorized by the user.
  • [SAFE]: Persistence mechanisms, privilege escalation, and obfuscation techniques are absent from the codebase and instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 03:36 AM
Security Audit — agent-trust-hub — cover-letter