Professor Match
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run the
datecommand via Bash to include the current date in questions about application deadlines.\n- [DATA_EXFILTRATION]: User CV profile data is read from${CLAUDE_PLUGIN_ROOT}/.local.mdand shared with external search engines to find relevant professors. While necessary for the skill's purpose, this represents a disclosure of personal information to third-party services.\n- [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection (Category 8) because it retrieves and analyzes content from untrusted external web pages.\n - Ingestion points: Data is read from professor homepages and search engine results.\n
- Boundary markers: There are no delimiters or instructions to ignore embedded commands in the fetched web content.\n
- Capability inventory: The agent has the ability to execute Bash commands and perform network-based searches.\n
- Sanitization: No sanitization is applied to external content before it is processed for alignment analysis.
Audit Metadata