career-growth
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from multiple sources which could be used to influence agent behavior through embedded instructions.
- Ingestion points: Local resume files, source code and commit history from user repositories, Azure DevOps work items, and pasted text from LinkedIn profiles or external certificates.
- Boundary markers: The instructions lack specific boundary delimiters or safety prompts to prevent the agent from following instructions contained within the ingested evidence files.
- Capability inventory: The agent has permissions to perform network requests for market surveys, write files to the local file system, execute
gitcommands, and run generated scripts for data analysis. - Sanitization: There is no evidence of text sanitization or filtering applied to ingested data before it is processed by the agent or included in reports.
- [DYNAMIC_EXECUTION]: The agent is required to generate and run scripts locally to process market data.
- Evidence: Station 2 (Market) requires that headline numbers for market recommendations be "computed from source values, once, in a script" to ensure accuracy. This involves generating code that processes data gathered from external web sources.
- [COMMAND_EXECUTION]: The skill performs various shell operations to manage the user's career data.
- Evidence: The skill instructions specify scanning git commit history across multiple repositories and performing "assisted commits" to a dedicated career repository (Step 0 and Station 1).
Audit Metadata