mapa-atratividade-vagas

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes local Python scripts included in the repository (scripts/render_radar.py) to generate SVG visualizations from analyzed job data. This is a standard use of helper scripts for visualization tasks.
  • [EXTERNAL_DOWNLOADS]: The skill references the Chart.js library via Cloudflare's CDN in its HTML export template. This is a well-known service and the reference is consistent with the skill's visualization features.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests job descriptions from the Gupy portal using MCP tools (search_jobs, get_job_by_id). This external content is processed to extract scoring dimensions. While there are no explicit sanitization steps mentioned for the job descriptions, the skill's actions are focused on data analysis and do not involve dangerous operations with the processed text.
  • [DYNAMIC_EXECUTION]: The agent is instructed to pass JSON data to a Python script for rendering. This involves local execution of code shipped with the skill and is used for its primary purpose of data visualization.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 12:22 AM
Security Audit — agent-trust-hub — mapa-atratividade-vagas