interview-simulator

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were detected. The skill functions as an architectural blueprint and coaching tool for interview preparation.
  • [EXTERNAL_DOWNLOADS]: The skill references several external dependencies and APIs, including Hume AI, ElevenLabs, Supabase, and Anthropic. These are well-known technology providers. The setup instructions correctly guide users to install these via standard package managers (NPM) and configure API keys in local environment files (".env.local"), which is an industry-standard security practice.
  • [DATA_EXFILTRATION]: No evidence of unauthorized data access or exfiltration. The proctoring engine uses MediaPipe Face Mesh, which runs entirely in the user's browser via TensorFlow.js, ensuring that biometric data (gaze tracking) is processed locally and not transmitted to external servers.
  • [PROMPT_INJECTION]: The system prompts for the various interviewer personas (Friendly, Neutral, Adversarial, Socratic) are well-defined and focused on simulating realistic interview scenarios. There are no instructions that attempt to bypass AI safety filters or override core agent behavior.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes user-generated transcripts and external API responses, it does not include any vulnerable code execution paths that would allow these inputs to compromise the host environment. The risk of indirect prompt injection is minimized by the intended use case of private mock interview simulation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:13 AM
Security Audit — agent-trust-hub — interview-simulator