hiring-signal-outreach

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests and processes untrusted data from external job boards and search results to generate outreach content.\n * Ingestion points: Company lists and job postings retrieved from external tools in Step 1 (SKILL.md).\n * Boundary markers: No delimiters or explicit instructions are provided to the model to ignore embedded instructions within the job postings.\n * Capability inventory: The skill has access to web-search, job-search, contact-finding, and email-drafting capabilities.\n * Sanitization: There is no evidence of sanitization or filtering of the job description text before it is used in Step 4 for email drafting.\n- [EXTERNAL_DOWNLOADS]: Fetches job postings and contact information from well-known services including LinkedIn, Indeed, Apollo, and Clearbit (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 10:48 AM