building-a-promotion-case
Pass
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of instructional Markdown files, templates, and evaluation metadata. There are no executable scripts, shell commands, or network operations included in the skill package.
- [DATA_EXPOSURE]: The skill incorporates strong data protection guidance, explicitly instructing users to redact PII and anonymize sensitive company data before providing work examples for analysis (documented in SKILL.md and references/INTAKE.md).
- [PROMPT_INJECTION]: The instructions focus purely on the intended career development use case. There are no attempts to bypass safety filters, extract system prompts, or override agent operational constraints.
- [EXTERNAL_DOWNLOADS]: The skill does not define any external dependencies, package installations (pip/npm), or remote code execution patterns. All resources required for the skill are contained within the provided reference files.
- [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process user-provided work descriptions and rubrics, it lacks the high-risk capabilities (such as network access or file system write permissions) that would allow an indirect injection attack to cause harm.
Audit Metadata