output-career-portfolio

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes a command-line interface tool (portfolio build) to transform a validated career release directory into a static portfolio projection.- [INDIRECT_PROMPT_INJECTION]: The skill processes external 'career knowledge releases' which are identified as untrusted content sources. This creates an ingestion surface for potentially malicious embedded instructions. The skill addresses this by requiring explicit validation checks, mandatory escaping of all text and attributes, and the implementation of a restrictive Content Security Policy (CSP) to prevent the execution of scripts or remote assets within the generated portfolio.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:16 PM
Security Audit — agent-trust-hub — output-career-portfolio