hiring
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and execute the
@coldiq/mcppackage using thenpxutility. This is a vendor-owned package hosted on the official npm registry. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources such as job boards and LinkedIn profiles, representing an attack surface for indirect instructions. * Ingestion points: Data enters through tool calls such as
mcp__coldiq__search_jobsand raw scraping of job boards or social profiles. * Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded prompts within the external data. * Capability inventory: The agent has access to tools for network-based searches and job intelligence data acquisition. * Sanitization: There are no documented steps for validating or sanitizing the content retrieved from external sources before processing.
Audit Metadata