great-resume
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Provides instructions for the agent to execute a local Python script (scripts/validate_claim_ledger.py) to validate the structure of the career ledger JSON file. This is a standard utility for maintaining data integrity.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user content such as resumes and project descriptions to perform its primary function.
- Ingestion points: Reads existing resumes, project descriptions, works, screenshots, and public repository data (SKILL.md).
- Boundary markers: Employs a 'Claim-Evidence Ledger' and 'Business Analysis Evidence' workflow to establish a factual baseline and separate verified evidence from qualitative claims (references/claim-evidence-ledger.md).
- Capability inventory: Limited to text generation for career materials and execution of a local JSON validation script.
- Sanitization: Includes explicit instructions to exclude sensitive data such as passwords, internal code, and client secrets from the evidence files (references/claim-evidence-ledger.md).
Audit Metadata