career-portfolio
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided project descriptions and portfolio data, which presents an attack surface for indirect prompt injection. This surface is evaluated as safe given the skill's restricted capabilities and intended use as an informational guide.
- Ingestion points: User-inputted project details and existing portfolio text as described in
SKILL.md. - Boundary markers: Absent; there are no explicit delimiters or specific instructions for the AI to ignore embedded commands within user content.
- Capability inventory: Limited to text generation, structured layout recommendations, and multi-step reasoning using standard MCP tools; no access to shell commands, sensitive files, or network-write operations.
- Sanitization: Absent; the skill does not define validation or filtering for user-provided input strings.
Audit Metadata