career-consult

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified. The skill performs intended operations within the user's Google Workspace environment and uses the author's own infrastructure for configuration.
  • [COMMAND_EXECUTION]: The skill documentation includes an installation command using npx that targets the author's GitHub repository (github.com/peter-tu-zynkr/zynkr-skill-builder). This is a legitimate vendor resource for skill deployment and management.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill handles personally identifiable information (PII) such as client names, contact details, and professional history. This data is managed entirely within the user's own Google Drive folders (1tkcJeV8silMmCZgNoOz0-SYXsEIQX2Sd) and Google Workspace account (peter_tu@zynkr.ai), following the intended workflow for career coaching.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from Gmail messages and PDF attachments (CVs). It mitigates potential instruction injection by enforcing a structured template and requiring that any content inferred by the AI rather than stated by the client be explicitly marked with the label 〔推測,需確認〕 for manual review.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:10 AM
Security Audit — agent-trust-hub — career-consult