hr-network-analyst

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONOBFUSCATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted data from the open web using tools such as WebSearch, WebFetch, firecrawl_search, and brave_web_search.
  • Ingestion points: External data enters the agent context through search results and web scraping tools referenced in SKILL.md.
  • Boundary markers: The instructions do not define clear delimiters or "ignore embedded instructions" warnings for the processed data.
  • Capability inventory: The skill has Write and Edit capabilities, and the reference files provide code for performing network operations (requests).
  • Sanitization: There is no explicit mention of sanitizing or escaping the retrieved external content before processing.
  • [COMMAND_EXECUTION]: The skill's reference directory contains numerous Python scripts and code patterns (e.g., in references/algorithms.md and references/data-sources-implementation.md). While the skill does not automatically execute these via a listed tool, it explicitly instructs the agent to use these patterns to "Compute centrality" and "Analyze professional network," which may lead to local code execution if a REPL tool is available in the agent's environment.
  • [OBFUSCATION]: In references/data-sources.md, the skill provides specific implementation logic (human_like_delay, scrape_with_delays) designed to evade bot detection and automated scraping protections on external platforms like LinkedIn. This includes randomized sleep intervals and "jitter" to mimic human behavior and bypass platform security controls.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:13 AM
Security Audit — agent-trust-hub — hr-network-analyst