Professor Match

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to run the date command via Bash to include the current date in questions about application deadlines.\n- [DATA_EXFILTRATION]: User CV profile data is read from ${CLAUDE_PLUGIN_ROOT}/.local.md and shared with external search engines to find relevant professors. While necessary for the skill's purpose, this represents a disclosure of personal information to third-party services.\n- [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection (Category 8) because it retrieves and analyzes content from untrusted external web pages.\n
  • Ingestion points: Data is read from professor homepages and search engine results.\n
  • Boundary markers: There are no delimiters or instructions to ignore embedded commands in the fetched web content.\n
  • Capability inventory: The agent has the ability to execute Bash commands and perform network-based searches.\n
  • Sanitization: No sanitization is applied to external content before it is processed for alignment analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 07:28 AM
Security Audit — agent-trust-hub — Professor Match