finding-startup-employees-for-recruiting
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes external actors and tools from Apify (apidojo/twitter-user-scraper, apidojo/tweet-scraper). These are used according to their intended purpose for the recruitment workflow and originate from the skill's own author namespace.
- [CREDENTIALS_UNSAFE]: The skill correctly instructs the user to manage the
APIFY_TOKENvia environment variables or a.envfile, which is the standard safe practice for secret management. - [COMMAND_EXECUTION]: The skill provides example shell commands (curl, node) to interact with the Apify API. These are standard integration snippets and do not involve suspicious behaviors like piping to bash or privilege escalation.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from Twitter profiles (bios, tweets) to score candidates. While this is an ingestion surface, the processing is limited to scoring and formatting, which poses a low risk. The skill description includes clear boundary markers for how data should be filtered and presented.
Audit Metadata