suggest-skills
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from external sources via WebSearch and WebFetch to identify required skills, creating a surface for indirect prompt injection.
- Ingestion points: External job postings, company briefs, and domain notes fetched during the Extract demand signals step in SKILL.md.
- Boundary markers: Absent; there are no instructions or delimiters defined to prevent the agent from following malicious instructions embedded in the fetched content.
- Capability inventory: The skill utilizes Read (ground-truth.md), Write (recommendations/), and restricted Bash tools (mkdir, test, date).
- Sanitization: Absent; untrusted content is analyzed directly without escaping or validation before being processed by the agent.
Audit Metadata