company-research
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses web search and fetch tools to gather data from career and compensation websites. This is the primary function of the skill and uses well-known services relevant to company research.\n- [COMMAND_EXECUTION]: Employs shell commands to read internal skill definition files (.claude/skills/generate-targets/SKILL.md) for the purpose of task delegation. This usage is restricted to local configuration files and represents a standard pattern for modular agent operations.\n- [DATA_EXFILTRATION]: Accesses user-defined career planning data (career-plan.yaml) to contextualize research queries. This data is processed locally and is used solely to tailor the research output as intended by the skill's design.\n- [PROMPT_INJECTION]: The skill ingests data from external websites which could potentially contain indirect prompt injection attacks designed to influence agent behavior.\n
- Ingestion points: External websites via WebFetch (e.g., Glassdoor, Blind, levels.fyi).\n
- Boundary markers: None explicitly specified in the skill instructions.\n
- Capability inventory: File writing, bash access, web fetching, and blackboard state management.\n
- Sanitization: No explicit sanitization of external web content is described.
Audit Metadata