academic-cv-builder
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: A comprehensive review of the skill files revealed no malicious patterns, obfuscation, or security vulnerabilities.
- [NO_CODE]: The skill is comprised entirely of markdown instructions and evaluation criteria; it contains no Python scripts, JavaScript files, shell commands, or external dependencies.
- [PROMPT_INJECTION]: No instructions were found that attempt to bypass AI safety filters, extract system prompts, or override agent behavior constraints.
- [DATA_EXFILTRATION]: The skill does not contain any commands to access sensitive directories (e.g., .ssh, .aws) or transmit data to external domains.
- [INDIRECT_PROMPT_INJECTION]: Analysis of the untrusted data ingestion surface: (1) Ingestion points: User-supplied resume and CV material identified in SKILL.md. (2) Boundary markers: No explicit delimiters or ignore-instructions are defined. (3) Capability inventory: The skill possesses no tools, scripts, or command-line capabilities. (4) Sanitization: No input validation is present. The finding is safe as the skill lacks any capabilities that could be exploited via malicious input.
Audit Metadata