hiring-signal-outreach
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to perform searches across multiple platforms including LinkedIn Jobs, Indeed, and Google Jobs (Step 1). These operations are legitimate and necessary for identifying the hiring signals specified in the skill's description.- [DATA_EXFILTRATION]: The workflow involves moving gathered lead data (contacts and company profiles) to external outreach services such as Smartlead, Lemlist, or Outreach.io (Step 5). This data transfer is the intended primary outcome of the skill and is triggered by the user.- [PROMPT_INJECTION]: The skill ingests untrusted data from the web in the form of job descriptions (Step 1), which could theoretically contain instructions designed to influence the email drafting process. This surface for indirect prompt injection is mitigated by mandatory human checkpoints before campaign launch.
- Ingestion points: Job descriptions summaries from LinkedIn, Indeed, and Apollo (SKILL.md Step 1).
- Boundary markers: Not explicitly defined in the instructions.
- Capability inventory: File system write for configuration (SKILL.md Step 0), web search capability (Step 1), and data handoff to outreach tools (Step 5).
- Sanitization: No explicit sanitization of job description content is described.
Audit Metadata