building-a-promotion-case

Pass

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional Markdown files, templates, and evaluation metadata. There are no executable scripts, shell commands, or network operations included in the skill package.
  • [DATA_EXPOSURE]: The skill incorporates strong data protection guidance, explicitly instructing users to redact PII and anonymize sensitive company data before providing work examples for analysis (documented in SKILL.md and references/INTAKE.md).
  • [PROMPT_INJECTION]: The instructions focus purely on the intended career development use case. There are no attempts to bypass safety filters, extract system prompts, or override agent operational constraints.
  • [EXTERNAL_DOWNLOADS]: The skill does not define any external dependencies, package installations (pip/npm), or remote code execution patterns. All resources required for the skill are contained within the provided reference files.
  • [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process user-provided work descriptions and rubrics, it lacks the high-risk capabilities (such as network access or file system write permissions) that would allow an indirect injection attack to cause harm.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 16, 2026, 09:44 AM