CV Polish
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill follows a standard workflow for document analysis and improvement. It uses a local configuration file (
.local.md) to manage state and interacts with the user to gather requirements. All file operations (reading the CV and providing edits) are transparent and performed at the user's request.\n- [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection as it processes untrusted content from user-supplied CV files.\n - Ingestion points: CV content is ingested via the Read tool in Step 1 of the Standard Flow.\n
- Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions to encapsulate the ingested CV text.\n
- Capability inventory: The agent has permissions to read files and performs file modifications if the user selects the direct edit mode.\n
- Sanitization: No explicit sanitization or filtering of the CV content is described before the analysis phase.
Audit Metadata