resume-tailor-diagram

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted data from user-supplied Markdown files and chat dialogue to generate diagrams and interview guides. This creates an indirect prompt injection surface where malicious instructions hidden in project descriptions could influence the agent's behavior.
  • Ingestion points: User-provided Markdown files (e.g., in data/projects/) and interactive chat descriptions.
  • Boundary markers: The skill lacks explicit markers or delimiters to separate processed data from internal instructions.
  • Capability inventory: The agent reads from data/resume.md and experience-bank.md, and writes to paths within the output/ directory.
  • Sanitization: No input validation or filtering of the project descriptions is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 09:18 AM
Security Audit — agent-trust-hub — resume-tailor-diagram