openjobs-company-search
Pass
Audited by Gen Agent Trust Hub on Jun 30, 2026
Risk Level: SAFE
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill correctly handles the
MIRA_KEYauthentication token as an environment variable and provides explicit directives to the agent never to print, log, or request the key from the user. - [PROMPT_INJECTION]: The skill includes safety guardrails that instruct the agent to treat external data as untrusted content and to ignore any potential instructions found in remote text. The static analysis flag regarding concealment was evaluated as a false positive, as the instructions are designed to enforce clean UI presentation and security best practices for secret handling.
- [COMMAND_EXECUTION]: Command usage is limited to standard environment validation and legitimate API requests via
curltargeting the vendor's official endpoint (mira-api.openjobs-ai.com). - [EXTERNAL_DOWNLOADS]: The skill communicates exclusively with the author's verified infrastructure and explicitly forbids self-updating or the execution of remote instructions.
Audit Metadata