CV Polish

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill follows a standard workflow for document analysis and improvement. It uses a local configuration file (.local.md) to manage state and interacts with the user to gather requirements. All file operations (reading the CV and providing edits) are transparent and performed at the user's request.\n- [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection as it processes untrusted content from user-supplied CV files.\n
  • Ingestion points: CV content is ingested via the Read tool in Step 1 of the Standard Flow.\n
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions to encapsulate the ingested CV text.\n
  • Capability inventory: The agent has permissions to read files and performs file modifications if the user selects the direct edit mode.\n
  • Sanitization: No explicit sanitization or filtering of the CV content is described before the analysis phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 07:27 AM
Security Audit — agent-trust-hub — CV Polish