hr-network-analyst
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONOBFUSCATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted data from the open web using tools such as
WebSearch,WebFetch,firecrawl_search, andbrave_web_search. - Ingestion points: External data enters the agent context through search results and web scraping tools referenced in
SKILL.md. - Boundary markers: The instructions do not define clear delimiters or "ignore embedded instructions" warnings for the processed data.
- Capability inventory: The skill has
WriteandEditcapabilities, and the reference files provide code for performing network operations (requests). - Sanitization: There is no explicit mention of sanitizing or escaping the retrieved external content before processing.
- [COMMAND_EXECUTION]: The skill's reference directory contains numerous Python scripts and code patterns (e.g., in
references/algorithms.mdandreferences/data-sources-implementation.md). While the skill does not automatically execute these via a listed tool, it explicitly instructs the agent to use these patterns to "Compute centrality" and "Analyze professional network," which may lead to local code execution if a REPL tool is available in the agent's environment. - [OBFUSCATION]: In
references/data-sources.md, the skill provides specific implementation logic (human_like_delay,scrape_with_delays) designed to evade bot detection and automated scraping protections on external platforms like LinkedIn. This includes randomized sleep intervals and "jitter" to mimic human behavior and bypass platform security controls.
Audit Metadata