match-requirement

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a bash entrypoint (run.sh) to manage environment setup and execute a Python script (match_requirement.py) via uv run. This is a standard pattern for CLI tools and does not involve unsafe interpolation of user input into shell commands.
  • [EXTERNAL_DOWNLOADS]: The run.sh script downloads standard, well-known Python libraries (httpx, loguru, tenacity) using the uv package manager. These are established libraries from the official Python Package Index (PyPI).
  • [DATA_EXPOSURE]: The skill communicates with a local memory service via a Unix domain socket (/run/user/1000/embry/memory.sock) or a local HTTP endpoint (http://localhost:8601). These are local communication paths for internal system components and do not represent external exfiltration.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes requirement text from a data lake. While this text is technically untrusted data, it is passed to a backend service for matching. The skill implementation includes boundary markers (e.g., character limits in SKILL.md) and routes low-confidence or conflicting results to a pending_review queue for human oversight, which serves as a mitigation for potential injection or semantic errors.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — match-requirement