jobdanmark-search

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches and processes job descriptions and details from an external source (jobdanmark.dk). These descriptions are user-generated content (by employers) and are returned to the agent context without sanitization or boundary markers. A malicious job posting could contain instructions designed to influence the agent's behavior.
  • Ingestion points: Job descriptions and metadata are fetched in 'cli/src/commands/detail.ts' and 'cli/src/commands/search.ts'.
  • Boundary markers: The skill does not use specific delimiters or instructions to the agent to ignore content within the job descriptions.
  • Capability inventory: The agent is permitted to execute the skill's CLI commands via the 'Bash' tool, as specified in the 'SKILL.md' frontmatter.
  • Sanitization: The 'description' field from the JSON-LD data is passed directly to the output without sufficient filtering or escaping to prevent prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 09:02 PM