job-hunt-tailor

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external content (Job Descriptions) which creates a surface for indirect prompt injection attacks.
  • Ingestion points: Reads user-provided files such as resume.md and jd-pool/<id>.md into the agent context.
  • Boundary markers: The skill does not implement explicit boundary markers or instructions to disregard embedded commands in the source documents.
  • Capability inventory: The skill performs local file read and write operations within the designated work_dir.
  • Sanitization: There is no technical sanitization of input data, although the prompt contains strict internal guidelines and 'Ethical Boundaries' to prevent the fabrication of information.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 07:04 PM
Security Audit — agent-trust-hub — job-hunt-tailor