boss-job-hunter

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests job descriptions from the BOSS Zhipin platform to analyze and match them against user resumes. This ingestion of external, untrusted data represents an indirect prompt injection surface where a malicious employer could attempt to influence the agent's behavior. However, the skill mitigates this risk through a rigorous matching protocol and confirmation checks.
  • Ingestion points: Job descriptions are extracted from the BOSS website using integrated browser tools or provided by the user (SKILL.md, jd-match-gate.md).
  • Boundary markers: The skill uses a structured 'JD match gate' and 'pre-recommendation check' to isolate and verify external data before it affects the final output.
  • Capability inventory: The agent can read local files (resumes), analyze data, and output suggestions; it lacks capabilities for arbitrary system command execution or unauthorized network exfiltration.
  • Sanitization: The instructions explicitly forbid fabricating resume content and emphasize factual, evidence-based matching, providing a safeguard against deceptive external instructions.
  • [DATA_EXFILTRATION]: The skill processes highly sensitive personal information, including resumes and professional profiles. It adheres to strict privacy rules, as defined in the state and memory model, which require explicit user permission before any data is stored or moved to remote storage. No unauthorized data transmission patterns were found.
  • [COMMAND_EXECUTION]: The skill makes use of browser-control tools and plugins (e.g., Chrome plugins, Kimi WebBridge) to search for job listings. These tools are used solely for the stated purpose of job discovery and are subject to the platform's standard security boundaries and user oversight.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 08:18 AM
Security Audit — agent-trust-hub — boss-job-hunter