academic-cv-builder

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: A comprehensive review of the skill files revealed no malicious patterns, obfuscation, or security vulnerabilities.
  • [NO_CODE]: The skill is comprised entirely of markdown instructions and evaluation criteria; it contains no Python scripts, JavaScript files, shell commands, or external dependencies.
  • [PROMPT_INJECTION]: No instructions were found that attempt to bypass AI safety filters, extract system prompts, or override agent behavior constraints.
  • [DATA_EXFILTRATION]: The skill does not contain any commands to access sensitive directories (e.g., .ssh, .aws) or transmit data to external domains.
  • [INDIRECT_PROMPT_INJECTION]: Analysis of the untrusted data ingestion surface: (1) Ingestion points: User-supplied resume and CV material identified in SKILL.md. (2) Boundary markers: No explicit delimiters or ignore-instructions are defined. (3) Capability inventory: The skill possesses no tools, scripts, or command-line capabilities. (4) Sanitization: No input validation is present. The finding is safe as the skill lacks any capabilities that could be exploited via malicious input.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 03:22 AM
Security Audit — agent-trust-hub — academic-cv-builder