zoho-recruit

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Communicates with vendor-specific infrastructure including gateway.maton.ai, ctrl.maton.ai, and connect.maton.ai for API proxying and OAuth management.
  • [COMMAND_EXECUTION]: Provides numerous Python and shell snippets demonstrating how to interact with the API using subprocess execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from an external API, creating an attack surface for instructions embedded in external content.
  • Ingestion points: Retrieves candidate profiles, job descriptions, and application data from Zoho Recruit API endpoints.
  • Boundary markers: Lacks specific delimiters or 'ignore embedded instructions' warnings for processed data.
  • Capability inventory: Allows for data modification on the Zoho Recruit platform and Python code execution as part of its documented functionality.
  • Sanitization: Does not mention explicit validation or sanitization of the external data before it is presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 01:52 PM
Security Audit — agent-trust-hub — zoho-recruit