apply-recommendation-letter-strategist
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No evidence of prompt injection or behavior override patterns. The instructions focus on structured workflows for academic advising and explicitly prohibit the generation of fake documents or impersonation.
- [DATA_EXFILTRATION]: No network operations, hardcoded credentials, or sensitive file path access detected. The skill operates solely on text provided by the user within the agent's context.
- [OBFUSCATION]: No obfuscated content, encoded strings, zero-width characters, or homoglyphs were found in the skill instructions or evaluation files.
- [REMOTE_CODE_EXECUTION]: The skill does not perform any external downloads, package installations, or remote script execution. There are no scripts or configuration files that trigger code execution.
- [COMMAND_EXECUTION]: No shell commands, subprocess calls, or dynamic execution patterns (like eval or exec) are present.
- [INDIRECT_PROMPT_INJECTION]: While the skill processes user-supplied data (CVs, SOPs, recommender details), it lacks dangerous capabilities such as file-system writes or network requests, rendering the attack surface for indirect injection negligible.
- [DYNAMIC_CONTEXT_INJECTION]: No use of shell-execution placeholders (
!command) was detected in the skill metadata or instructions.
Audit Metadata