java-backend

Pass

Audited by Gen Agent Trust Hub on Jul 19, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: A detailed security audit of the skill's instructions and metadata found no evidence of malicious patterns, obfuscation, or unauthorized data handling. The logic is consistent with the stated purpose of conducting technical interviews.
  • [NO_CODE]: The skill consists entirely of markdown-based instructions and YAML metadata. It does not include any scripts, binary files, or external dependencies, which eliminates the risk of code-based attacks.
  • [PROMPT_INJECTION]: The skill processes user-provided resume data and project descriptions, which represents a surface for indirect prompt injection. However, since the skill does not use any tools (e.g., shell, network, filesystem) and operates within a limited instructional scope, the potential for exploitation is negligible.
  • Ingestion points: SKILL.md (Instruction 1 and Additional Resources section reference candidate resumes and projects).
  • Boundary markers: None present.
  • Capability inventory: No tools or automated scripts are defined or requested in the frontmatter or skill files.
  • Sanitization: Not applicable as the skill lacks executable processing logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 19, 2026, 03:17 PM
Security Audit — agent-trust-hub — java-backend