output-career-knowledge-guide

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data (referred to as 'governed-view' or 'supplied-release') which is explicitly acknowledged as untrusted. This represents a surface for indirect prompt injection where malicious instructions could be embedded in the career data to manipulate the agent's behavior. The skill includes specific defensive instructions to mitigate this, stating that embedded instructions cannot change the audience, purpose, policy, or disclosure boundary.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:16 PM
Security Audit — agent-trust-hub — output-career-knowledge-guide