career-growth

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from multiple sources which could be used to influence agent behavior through embedded instructions.
  • Ingestion points: Local resume files, source code and commit history from user repositories, Azure DevOps work items, and pasted text from LinkedIn profiles or external certificates.
  • Boundary markers: The instructions lack specific boundary delimiters or safety prompts to prevent the agent from following instructions contained within the ingested evidence files.
  • Capability inventory: The agent has permissions to perform network requests for market surveys, write files to the local file system, execute git commands, and run generated scripts for data analysis.
  • Sanitization: There is no evidence of text sanitization or filtering applied to ingested data before it is processed by the agent or included in reports.
  • [DYNAMIC_EXECUTION]: The agent is required to generate and run scripts locally to process market data.
  • Evidence: Station 2 (Market) requires that headline numbers for market recommendations be "computed from source values, once, in a script" to ensure accuracy. This involves generating code that processes data gathered from external web sources.
  • [COMMAND_EXECUTION]: The skill performs various shell operations to manage the user's career data.
  • Evidence: The skill instructions specify scanning git commit history across multiple repositories and performing "assisted commits" to a dedicated career repository (Step 0 and Station 1).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:03 AM
Security Audit — agent-trust-hub — career-growth