saramin-talent-search

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches instructions and file stubs from the author's official GitHub repository and via a vendor-specific Node.js package (@nomadamas/k-skill). These resources are used to maintain the latest functional guidelines for the skill.
  • [COMMAND_EXECUTION]: The SKILL.md file provides commands for the user to run using npx to retrieve extended instructions and file lists. These commands execute the vendor's CLI tool to prepare the environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes candidate information from the Saramin recruitment portal. While this involves ingesting external data, the instructions include explicit boundaries to only read visible/masked data and avoid interaction with sensitive or paid elements, minimizing the risk of malicious instruction execution from the profile data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 05:44 AM
Security Audit — agent-trust-hub — saramin-talent-search