resume-auditor
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill's functionality is transparent and matches its described purpose of auditing resumes and CVs.
- [COMMAND_EXECUTION]: Executes a local script
profile-strength.mjsvia Node.js to generate profile metrics. This script is a component of the skill's internal directory structure and does not involve remote code execution or untrusted downloads. - [PROMPT_INJECTION]: The skill ingests untrusted data from user resumes and job descriptions, creating an indirect prompt injection surface. 1. Ingestion points:
my-documents/resume.mdandmy-documents/cv.md. 2. Boundary markers: Absent. 3. Capability inventory: Writes reports tomy-documents/reports/and executes a local assessment script. 4. Sanitization: Not explicitly present. This surface is considered low-risk given the restricted capabilities and the intended use case.
Audit Metadata