resume-ats-beater

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits a susceptibility to indirect prompt injection due to the processing of untrusted external data.
  • Ingestion points: Untrusted data enters the agent context through the curriculo_atual, perfil_linkedin, and descricao_vaga parameters defined in SKILL.md.
  • Boundary markers: The instructions lack explicit boundary markers or delimiters to isolate user-provided data from the skill's system instructions, nor do they include warnings to ignore embedded commands.
  • Capability inventory: The skill does not perform any high-risk operations such as shell command execution, file system modifications, or network exfiltration across its scripts or referenced files.
  • Sanitization: There are no instructions to sanitize or validate the input text for malicious payloads before it is processed by the AI.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:18 PM
Security Audit — agent-trust-hub — resume-ats-beater