best-practices-opportunities

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for ingesting and processing untrusted job descriptions (JDs) from external sources, including APIs and web browsing.
  • Ingestion points: Job description text acquired via ATS APIs, DOM surfing, or evidence URLs (Section 1), and employer/domain research via brave-search.
  • Capability inventory: The skill composes brave-search and agentic-evals to process this data, and instructs subagents to produce scores, verdicts, and application drafts.
  • Sanitization: The skill uses a vocabulary-driven entity extraction pass (Section 3) to filter relevance before LLM evaluation, which provides a layer of data validation.
  • Boundary markers: There are no explicit instructions to use delimiters or ignore embedded commands when the agent processes the external JD text.
  • [DATA_EXFILTRATION]: The skill instructions specify that opportunity data should be tracked and synchronized to a private repository (grahama1970/opportunities). As this repository belongs to the skill's author, this is considered a vendor-controlled data flow for persistence.
  • [DATA_EXPOSURE]: The agent is instructed to read from skills/monitor-opportunities/config/candidate_profile.json and the /memory directory to retrieve the user's personal profile, work authorization status, and location. These files contain sensitive personal information necessary for the skill's career evaluation functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — best-practices-opportunities