end-to-end-hiring-signal
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by processing untrusted external content.
- Ingestion points: Untrusted data is ingested from job boards (LinkedIn, Indeed, Apollo, Google Jobs) and social media (Hacker News, Reddit, Twitter/X).
- Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the pipeline description for handling scraped data.
- Capability inventory: The skill uses scraped content to perform web searches, find contacts, and draft personalized email sequences.
- Sanitization: The instructions do not specify any validation or sanitization of the scraped job description text before it is used as a hook in email drafting prompts.
- [DATA_EXFILTRATION]: The skill is designed to collect and transmit contact information to external platforms.
- Behavior: It searches for and caches contact details (PII) for hiring managers and other stakeholders.
- Exfiltration: The gathered data is explicitly packaged and sent to configured third-party outreach tools such as Smartlead, Instantly, Outreach.io, or Lemlist.
Audit Metadata