resume-auditor

Pass

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill's functionality is transparent and matches its described purpose of auditing resumes and CVs.
  • [COMMAND_EXECUTION]: Executes a local script profile-strength.mjs via Node.js to generate profile metrics. This script is a component of the skill's internal directory structure and does not involve remote code execution or untrusted downloads.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from user resumes and job descriptions, creating an indirect prompt injection surface. 1. Ingestion points: my-documents/resume.md and my-documents/cv.md. 2. Boundary markers: Absent. 3. Capability inventory: Writes reports to my-documents/reports/ and executes a local assessment script. 4. Sanitization: Not explicitly present. This surface is considered low-risk given the restricted capabilities and the intended use case.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 9, 2026, 02:29 PM
Security Audit — agent-trust-hub — resume-auditor