end-to-end-hiring-signal

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by processing untrusted external content.
  • Ingestion points: Untrusted data is ingested from job boards (LinkedIn, Indeed, Apollo, Google Jobs) and social media (Hacker News, Reddit, Twitter/X).
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the pipeline description for handling scraped data.
  • Capability inventory: The skill uses scraped content to perform web searches, find contacts, and draft personalized email sequences.
  • Sanitization: The instructions do not specify any validation or sanitization of the scraped job description text before it is used as a hook in email drafting prompts.
  • [DATA_EXFILTRATION]: The skill is designed to collect and transmit contact information to external platforms.
  • Behavior: It searches for and caches contact details (PII) for hiring managers and other stakeholders.
  • Exfiltration: The gathered data is explicitly packaged and sent to configured third-party outreach tools such as Smartlead, Instantly, Outreach.io, or Lemlist.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 03:06 PM
Security Audit — agent-trust-hub — end-to-end-hiring-signal