hiring-scorecard
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied job requirements and team context to generate a structured scorecard. This creates an attack surface where malicious instructions embedded in the input could influence the agent's output generation.\n
- Ingestion points: User-provided role context, job title, and requirements (SKILL.md).\n
- Boundary markers: Absent. The instructions do not specify delimiters or warnings to ignore embedded instructions within user input.\n
- Capability inventory: The skill uses Read, Write, Glob, and Grep tools to read reference files and write the final scorecard.md output (SKILL.md).\n
- Sanitization: Absent. There is no evidence of input validation or content filtering for external data.
Audit Metadata