job-post-builder
Pass
Audited by Gen Agent Trust Hub on May 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- Interaction with External Data: The skill is designed to search the web and read local documents to gather context for hiring documents, which presents a surface for indirect instructions. \n
- Ingestion points: Web search results (LinkedIn, Greenhouse, company career pages) and local file contents (Desktop/Google Drive) accessed via the file MCP. \n
- Boundary markers: No specific delimiters or instructions to ignore embedded commands are defined to wrap the ingested external data within the agent's context. \n
- Capability inventory: Includes browser automation (Claude in Chrome) for DocuSign integration, document creation via a docx tool, and email drafting via the Gmail MCP. \n
- Sanitization: No explicit sanitization or filtering of external content is mentioned before it is processed into final templates. \n
- Context: This capability involves processing external information; however, the risk is moderated by the skill's focus on drafting documents and the mandatory human review before any external action (like sending an envelope) is taken. \n- Browser Automation and Sensitive Actions: The skill uses automated browser flows to interact with DocuSign for offer letter delivery. \n
- The instructions mandate that DocuSign envelopes be saved as drafts rather than sent directly, ensuring a human review step is present before any external communication. \n
- It relies on the user's existing authenticated browser session for DocuSign access, which is a positive practice as it avoids the need for the agent to handle or store credentials directly. \n- Tool Integration (DocuSign, Gmail, File Access): The skill leverages platform tools for accessing local files and drafting emails. All externally-visible actions, such as drafting a fallback email or setting up a signature envelope, are subject to explicit user approval gates, which is a standard safety measure for autonomous agents.
Audit Metadata