skills/gresonkwan/jobok/job-ok/Gen Agent Trust Hub

job-ok

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes several Python scripts (extract_resume_text.py, normalize_jobs.py, score_job_matches.py) that the agent is instructed to execute for processing local files. These scripts handle text extraction, data normalization, and keyword scoring without any network operations.\n- [EXTERNAL_DOWNLOADS]: The documentation provides instructions to install the skill from a GitHub repository and to download optional Python dependencies (pdfplumber, python-docx) from PyPI or a well-known Chinese mirror. These sources are considered well-known and standard for software development.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and analyze untrusted data provided by the user, such as job descriptions and resumes. However, the skill instructions (SKILL.md) and rubrics include specific countermeasures, such as requiring evidence-based labels (e.g., 'needs_proof') and explicitly refusing to generate fabricated content.\n- [SAFE]: The skill implements safety features in its scoring logic, specifically searching for keywords related to common employment scams (e.g., 'training loans', 'guaranteed offers') to alert the user to potential risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 03:55 AM
Security Audit — agent-trust-hub — job-ok