best-practices-opportunities
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for ingesting and processing untrusted job descriptions (JDs) from external sources, including APIs and web browsing.
- Ingestion points: Job description text acquired via ATS APIs, DOM surfing, or evidence URLs (Section 1), and employer/domain research via
brave-search. - Capability inventory: The skill composes
brave-searchandagentic-evalsto process this data, and instructs subagents to produce scores, verdicts, and application drafts. - Sanitization: The skill uses a vocabulary-driven entity extraction pass (Section 3) to filter relevance before LLM evaluation, which provides a layer of data validation.
- Boundary markers: There are no explicit instructions to use delimiters or ignore embedded commands when the agent processes the external JD text.
- [DATA_EXFILTRATION]: The skill instructions specify that opportunity data should be tracked and synchronized to a private repository (
grahama1970/opportunities). As this repository belongs to the skill's author, this is considered a vendor-controlled data flow for persistence. - [DATA_EXPOSURE]: The agent is instructed to read from
skills/monitor-opportunities/config/candidate_profile.jsonand the/memorydirectory to retrieve the user's personal profile, work authorization status, and location. These files contain sensitive personal information necessary for the skill's career evaluation functionality.
Audit Metadata