resume-tailor
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Node.js scripts for workspace scaffolding, document exporting (PDF/DOCX), and tracking application momentum. These scripts are located within the skill's own directory structure under the {job_hunt_skills_root} path.\n- [EXTERNAL_DOWNLOADS]: The skill allows for the input of job posting URLs to analyze role requirements and company values. This is a standard functional requirement for the skill's purpose.\n- [DATA_EXFILTRATION]: The skill accesses and processes sensitive personal documents such as resumes, CVs, and story banks. However, all file operations are conducted within the user's local directory and no exfiltration to external domains was identified.\n- [PROMPT_INJECTION]: The skill ingests untrusted data from job postings, creating a surface for indirect prompt injection. Mitigation is present through a claim-verification workflow that validates output against an evidence layer before files are saved.
Audit Metadata