career-consult
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified. The skill performs intended operations within the user's Google Workspace environment and uses the author's own infrastructure for configuration.
- [COMMAND_EXECUTION]: The skill documentation includes an installation command using
npxthat targets the author's GitHub repository (github.com/peter-tu-zynkr/zynkr-skill-builder). This is a legitimate vendor resource for skill deployment and management. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill handles personally identifiable information (PII) such as client names, contact details, and professional history. This data is managed entirely within the user's own Google Drive folders (
1tkcJeV8silMmCZgNoOz0-SYXsEIQX2Sd) and Google Workspace account (peter_tu@zynkr.ai), following the intended workflow for career coaching. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from Gmail messages and PDF attachments (CVs). It mitigates potential instruction injection by enforcing a structured template and requiring that any content inferred by the AI rather than stated by the client be explicitly marked with the label
〔推測,需確認〕for manual review.
Audit Metadata