o1-petition
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-uploaded documents (CVs, letters, notices) which could contain malicious instructions. However, the skill provides clear defensive instructions to the agent to treat these files as data only, ignore any embedded commands, and inform the user if such commands are found.
- [EXTERNAL_DOWNLOADS]: The skill uses Python scripts to fetch official government forms from uscis.gov and academic publication data from the OpenAlex API (api.openalex.org). These are legitimate, well-known services relevant to the skill's purpose.
- [DATA_EXFILTRATION]: The skill includes an optional feature to contribute anonymous case data to the developer's GitHub repository. This process is transparently described, ensures strict anonymization of sensitive data, and mandates explicit user consent before any information is sent.
Audit Metadata