skills/ethan-rio/skills/cv-builder/Gen Agent Trust Hub

cv-builder

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the 'rendercv' package from the Python Package Index (PyPI) via pip install rendercv. This is a well-known open-source tool for LaTeX-based CV generation.
  • [COMMAND_EXECUTION]: The skill uses rendercv render to process YAML files and generate PDF outputs. This is the primary function of the skill and relies on the installed CLI tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data to generate resumes, which represents a potential injection surface.
  • Ingestion points: User-provided experience, education, and skill details provided via chat prompts or YAML configuration (SKILL.md).
  • Boundary markers: None detected in the provided instructions to delimit user data or warn the model about embedded instructions.
  • Capability inventory: Execution of shell commands via rendercv and PDF generation.
  • Sanitization: No explicit sanitization or validation of the input strings is mentioned before they are passed to the rendering engine.
  • [METADATA_POISONING]: The skill's metadata lists the author as 'claude-office-skills', which is inconsistent with the provided author context of 'ethan-rio'.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 10:55 AM
Security Audit — agent-trust-hub — cv-builder