job-description-analyzer

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [NO_CODE]: The skill is composed strictly of markdown instructions and static JSON evaluation files. It does not contain any executable scripts, binaries, or configuration files for package managers, ensuring no risk of traditional code execution or persistence.\n- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it processes untrusted external content as a primary function.\n
  • Ingestion points: The skill instructions in SKILL.md require the ingestion of job descriptions and candidate resumes provided by the user.\n
  • Boundary markers: There are no explicit delimiters or specific 'ignore' instructions implemented to isolate the external job description text from the agent's core processing logic.\n
  • Capability inventory: The skill has no defined capabilities or allowed tools; it cannot access the filesystem, perform network operations, or execute shell commands.\n
  • Sanitization: No input validation or filtering is performed on the ingested text to detect or strip potential injection payloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 10:03 AM
Security Audit — agent-trust-hub — job-description-analyzer