resume-review

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill functions as a set of instructional guidelines for auditing and improving engineering resumes. Analysis of the text and instructions revealed no malicious patterns, command execution, or unauthorized data access.
  • [DATA_EXFILTRATION]: The skill provides explicit instructions to protect sensitive information, such as avoiding the disclosure of proprietary processes or classified details in resumes. It also advises minimizing the inclusion of personal identifiers like physical addresses to reduce bias. No network exfiltration patterns were identified.
  • [EXTERNAL_DOWNLOADS]: The skill references established, well-known services such as Grammarly, Hemingway Editor, and LanguageTool to assist with proofreading. These references are for standard user-facing tools and do not involve automated code execution or suspicious downloads.
  • [PROMPT_INJECTION]: The skill processes untrusted user-provided resume data. 1. Ingestion points: Resume content is processed by the agent according to instructions in SKILL.md. 2. Boundary markers: Absent; no specific delimiters or instructions to ignore embedded commands. 3. Capability inventory: No high-risk capabilities such as subprocess calls, network operations, or file-writing are present. 4. Sanitization: Absent. Risk Assessment: The lack of dangerous tools restricts the potential risk of indirect prompt injection to benign text manipulation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 03:51 AM
Security Audit — agent-trust-hub — resume-review