hiring-screener

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [Indirect Prompt Injection Surface]: The skill is designed to ingest and process untrusted external data, such as job applications, resumes, and candidate emails, which could contain malicious instructions intended to bypass agent constraints or perform unauthorized actions.
  • Ingestion points: Untrusted content enters the agent's context through Gmail attachments, user-uploaded resumes, and shared cloud storage folders in Google Drive or Microsoft 365, as described in Step 3 of SKILL.md.
  • Boundary markers: The skill includes clear instructions in SKILL.md under the 'What not to do' section to treat all ingested text as data rather than commands. It also references a shared untrusted-content.md file for handling verification steps for suspicious content.
  • Capability inventory: The agent possesses capabilities to interact with external services, such as drafting and sending emails via Gmail, scheduling events on Google Calendar, routing documents through DocuSign, and handing off data to payroll systems like Gusto.
  • Sanitization: To mitigate risks, the skill mandates an anonymization pass in reference/fair_screening.md to strip non-rubric-relevant details before scoring. Critically, every high-impact action—including sending emails, invites, and payroll handoffs—requires explicit human approval before execution, as stated in SKILL.md and reference/candidate_comms.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:05 PM
Security Audit — agent-trust-hub — hiring-screener