generic-recruiting

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill incorporates strict data integrity rules, requiring candidates to be keyed by persistent profile URLs or platform-specific IDs. This practice prevents data spoofing or mismatching when ranking candidates from varied sources.
  • [SAFE]: Access to external Applicant Tracking Systems (ATS) is performed via platform-managed 'Kortix connectors'. This ensures that sensitive credentials and API tokens are not hardcoded or exposed within the skill's instructions.
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill processes untrusted input from candidate résumés and web profiles to generate fit and readiness scores. This creates a surface for indirect prompt injection where adversarial text in a CV could attempt to influence the LLM's scoring. The skill mitigates this risk by requiring 'evidence-grounded' reasoning, where the model must cite specific facts for every score assigned, ensuring outcomes are tied to real data rather than embedded instructions.
  • [COMMAND_EXECUTION]: The skill leverages 'website-building' and 'webapp' capabilities to render and deploy shared talent pool leaderboards. These operations are part of the core functionality and rely on specialized platform skills to manage the infrastructure and deployment safely.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 04:26 PM
Security Audit — agent-trust-hub — generic-recruiting