job-search
Pass
Audited by Gen Agent Trust Hub on Oct 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from job listings across LinkedIn, Hacker News, and Twitter/X.
- Ingestion points: Job descriptions and comments are retrieved via browser tools and APIs in SKILL.md.
- Boundary markers: The skill lacks explicit markers or instructions to treat external job descriptions as untrusted content, which could allow malicious postings to influence the agent's scoring or ranking behavior.
- Capability inventory: The skill utilizes
Bashfor network operations and hasWriteaccess to local files. - Sanitization: There is no evidence of sanitization or filtering applied to external job content before it is displayed to the user or saved to the local file system.
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to executecurlcommands to retrieve job data from the Hacker News Firebase API. This is a functional requirement of the skill. - [EXTERNAL_DOWNLOADS]: Fetches configuration and job data from Hacker News' official Firebase API at
hacker-news.firebaseio.com. This is an interaction with a well-known service.
Audit Metadata