job-hunt-tailor
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external content (Job Descriptions) which creates a surface for indirect prompt injection attacks.
- Ingestion points: Reads user-provided files such as
resume.mdandjd-pool/<id>.mdinto the agent context. - Boundary markers: The skill does not implement explicit boundary markers or instructions to disregard embedded commands in the source documents.
- Capability inventory: The skill performs local file read and write operations within the designated
work_dir. - Sanitization: There is no technical sanitization of input data, although the prompt contains strict internal guidelines and 'Ethical Boundaries' to prevent the fabrication of information.
Audit Metadata