salary-research
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests untrusted data from external websites and community forums.
- Ingestion points: Public salary platforms and anonymous community sources processed during Step 3 (Research) in
SKILL.md. - Boundary markers: Absent. The procedure does not specify delimiters or instructions to ignore embedded commands within the fetched data.
- Capability inventory: File system access via
ReadandWritetools, and restricted shell capabilities viaBash(mkdir,test,date) as defined in the frontmatter andProceduresection ofSKILL.md. - Sanitization: Absent. No explicit sanitization or validation of the fetched external content is mentioned before it is processed or stored in the cache.
Audit Metadata