chro-advisor

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill provides legitimate human resources advisory functionality and strategy frameworks.
  • [SAFE]: Analysis of the Python scripts (comp_benchmarker.py, hiring_plan_modeler.py) confirms they use only standard libraries for data processing and report generation. There are no attempts to perform network operations, execute arbitrary shell commands, or access sensitive system paths.
  • [SAFE]: No patterns of prompt injection, obfuscation, or metadata poisoning were found. The skill maintains a professional and transparent structure for its stated purpose.
  • [PROMPT_INJECTION]: The skill processes external data (e.g., company-context.md and user-provided JSON files). While this presents a theoretical surface for indirect prompt injection, the risk is negligible as the skill lacks high-privilege capabilities such as network access, file system writes, or system command execution to exploit such an injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 08:16 AM
Security Audit — agent-trust-hub — chro-advisor