skills/zal4dw/career-helper/tim/Gen Agent Trust Hub

tim

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a secure data persistence model for user preferences. It stores session state in a local file (career-helper-preferences.md) only after obtaining explicit user consent. For returning users, the skill performs an identity confirmation check before accessing or displaying information from previous sessions, which prevents unauthorized access to potentially sensitive career data in shared environments.
  • [SAFE]: The orchestrator architecture adheres to the principle of least privilege. It restricts its own tool usage to 'Agent' for dispatching sub-skills and 'Glob' for file system discovery. It explicitly avoids the use of high-risk tools such as 'Bash', 'WebSearch', or 'WebFetch' in its core instructions, delegating those capabilities to specialized sub-agents only as needed.
  • [SAFE]: Comprehensive analysis of the instructions and reference guides (Dyslexia Guide, Ikigai Guide, Routing Guide) found no evidence of prompt injection, obfuscation, or unauthorized network activity. The skill's operational logic is transparent and consistent with its stated purpose as a supportive career coach.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 02:59 AM
Security Audit — agent-trust-hub — tim