job-post-builder

Warn

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [OBFUSCATION]: Detection of homoglyph characters in domain names (e.g., 'hh.ru'). This technique involves using visually similar characters from different scripts to represent a domain, which is a common pattern for typosquatting or evading automated security filters.
  • [COMMAND_EXECUTION]: The skill utilizes browser automation (via 'Claude in Chrome') to navigate and interact with Electronic Document Management (EDO) services such as Diadoc, SBIS, and nopaper. Although the skill instructions include mandatory approval gates and draft-only constraints before final submission, the underlying capability to automate authenticated browser sessions on legal and financial platforms represents a high-privilege operations surface.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it ingests untrusted data from the web and processes it into documents.
  • Ingestion points: External job boards (hh.ru, Avito Работа, VK Работа), web search results, and local files found in user storage ('~~хранилище') or on the Desktop.
  • Boundary markers: Absent. There are no explicit instructions to the agent to disregard or delimit potential commands embedded within the retrieved job descriptions or local files.
  • Capability inventory: File system write access (via docx skill), browser automation for document upload, and email drafting capabilities ('~~почта').
  • Sanitization: Absent. No validation or sanitization protocols are defined for the content extracted from external job platforms before it is used to generate new hiring documents.
  • [EXTERNAL_DOWNLOADS]: The skill performs automated web searches and reads content from external third-party websites to analyze market trends and existing vacancy descriptions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 3, 2026, 06:57 PM
Security Audit — agent-trust-hub — job-post-builder