hiring

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to download and run the vendor's MCP server using npx -y @coldiq/mcp@latest. As the package is in the vendor's own namespace, it is considered a legitimate resource for the skill's intended functionality.
  • [COMMAND_EXECUTION]: Shell commands are used to configure the COLDIQ_API_KEY and execute the npx command to initialize the skill's environment.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from job boards and LinkedIn profiles (ingestion points in SKILL.md). It lacks explicit boundary markers or sanitization in the outreach templates. The skill's capabilities include calling MCP tools to search for jobs and signals. This creates an indirect prompt injection surface which is a known risk for skills processing external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 06:37 PM
Security Audit — agent-trust-hub — hiring