resume-craft

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of Markdown-based instructions and an MIT license. No code, scripts, or network operations are present.
  • [PROMPT_INJECTION]: The skill processes untrusted user input (resumes and JDs), creating a surface for indirect prompt injection. 1. Ingestion points: SKILL.md Phase 1 defines the collection of user resumes and job descriptions. 2. Boundary markers: No specific delimiters are defined to isolate untrusted data. 3. Capability inventory: No tools or code execution capabilities are used. 4. Sanitization: The 'Core Principles' section in SKILL.md instructs the agent to maintain data truthfulness and privacy. The overall risk is low due to the lack of available tools for exploitation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 12:27 PM
Security Audit — agent-trust-hub — resume-craft