hr-automation

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The ai_screening prompt template in SKILL.md interpolates untrusted resume data ({resume_text}) directly into the instructions. This creates a surface where adversarial text within a resume could influence the automated decision to hire or reject a candidate.
  • Ingestion points: SKILL.md (via the {resume_text} placeholder).
  • Boundary markers: Absent. The prompt lacks delimiters or instructions to ignore embedded commands.
  • Capability inventory: The skill can automatically trigger recruitment actions including advance_to_screening, auto_reject, and sending emails via integrated HRIS/ATS systems (Workday, BambooHR, Greenhouse).
  • Sanitization: Absent. There is no evidence of filtering or validation for the resume content before it is processed by the model.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:46 AM
Security Audit — agent-trust-hub — hr-automation