job-board-aggregator

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external job boards, which creates a vulnerability surface where malicious instructions hidden in job listings could affect agent behavior.
  • Ingestion points: Job titles, descriptions, and company data scraped from Indeed, Glassdoor, and LinkedIn (SKILL.md).
  • Boundary markers: Absent; there are no defined delimiters or instructions to ignore embedded commands in the processed data.
  • Capability inventory: Use of browser tools for navigation and data extraction (SKILL.md).
  • Sanitization: Absent; the skill does not include steps for sanitizing or validating external content before it enters the agent context.
  • [EXTERNAL_DOWNLOADS]: The skill references a third-party service, BirdProxies (birdproxies.com), for residential proxy services and includes promotional discount information.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 04:09 PM
Security Audit — agent-trust-hub — job-board-aggregator