job-application-optimizer

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted job descriptions and user resumes from the web and local filesystem, which creates a surface for potential indirect prompt injection. 1. Ingestion points: Uses WebFetch for job postings and Read for local resume files. 2. Boundary markers: No explicit isolation markers are used for external data. 3. Capability inventory: The skill utilizes Write and Edit tools to generate and modify application artifacts. 4. Sanitization: No input validation or sanitization is specified for the external job data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:44 AM
Security Audit — agent-trust-hub — job-application-optimizer