cover-letter-writing

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of markdown templates and instructional documentation. No executable scripts, third-party code, or remote dependencies are included.
  • [PROMPT_INJECTION]: The skill handles untrusted data from external sources, specifically job description URLs and company websites. It manages the risk of indirect prompt injection through a multi-layered validation framework: 1. Ingestion points: External URLs for job descriptions and company research as defined in SKILL.md. 2. Boundary markers: Explicit Truthfulness Guardrails that mandate grounding all claims in resume or verified company sources. 3. Capability inventory: The agent performs web research and exports documents in PDF/DOCX formats. 4. Sanitization: Quality hooks (pre-research and post-research) are used to validate company information and remove any facts that cannot be directly cited to verified sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:07 PM
Security Audit — agent-trust-hub — cover-letter-writing