hr-automation
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The
ai_screeningprompt template inSKILL.mdinterpolates untrusted resume data ({resume_text}) directly into the instructions. This creates a surface where adversarial text within a resume could influence the automated decision to hire or reject a candidate. - Ingestion points:
SKILL.md(via the{resume_text}placeholder). - Boundary markers: Absent. The prompt lacks delimiters or instructions to ignore embedded commands.
- Capability inventory: The skill can automatically trigger recruitment actions including
advance_to_screening,auto_reject, and sending emails via integrated HRIS/ATS systems (Workday, BambooHR, Greenhouse). - Sanitization: Absent. There is no evidence of filtering or validation for the resume content before it is processed by the model.
Audit Metadata