resume-match

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted data from resumes and job descriptions via text, files, and URLs. While it lacks explicit boundary markers or sanitization for these inputs, the risk of indirect prompt injection is mitigated by mandatory 'Honesty Principles' and 'Anti-Hallucination Rules' that strictly limit the agent's output to factual information found in the original documents and prevent the fabrication of credentials or instructions. Capabilities include file reading, web crawling via tools, and local file writing for reporting.
  • [COMMAND_EXECUTION]: The skill generates an HTML analysis report and saves it to a local directory ('test-output/'). This is a standard reporting feature and is governed by a detailed design specification provided in the skill's reference files.
  • [EXTERNAL_DOWNLOADS]: The skill accesses external URLs to fetch job descriptions and references Google Fonts for styling its HTML reports. These are legitimate uses of external resources related to its primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 08:58 AM
Security Audit — agent-trust-hub — resume-match