cv-builder

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for local processing of repository content to create professional documents. It does not exhibit malicious behavior such as data exfiltration or unauthorized network access.
  • [COMMAND_EXECUTION]: The instructions direct the agent to check for the presence of pandoc using which and to verify PDF extraction with pdftotext. These are standard, safe operations for the skill's purpose.
  • [EXTERNAL_DOWNLOADS]: The reference material includes documentation on how a user can manually install necessary fonts via the system package manager (dnf), which is a legitimate setup activity.
  • [PROMPT_INJECTION]: The skill processes repository files as input. Although this is a theoretical vector for indirect prompt injection, the skill's structured extraction process and rigorous quality gates act as significant mitigations.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 11:22 AM
Security Audit — agent-trust-hub — cv-builder