hr-tech-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines workflows and data structures for systems meant to ingest external, untrusted content, which represents a vulnerability surface for indirect prompt injection attacks.
- Ingestion points: The
ApplicantTrackingSystemandPerformanceManagementSysteminreferences/EXAMPLES.mdprocess candidate details (resumes, LinkedIn URLs) and employee feedback (notes, comments). - Boundary markers: The provided code examples and instructions do not include prompt delimiters or instructions for the agent to treat external data as untrusted content.
- Capability inventory: The skill is granted
Read,Write, andWebSearchpermissions, which could be leveraged if the agent acts on instructions hidden within ingested data. - Sanitization: There is no evidence of sanitization, validation, or escaping logic in the provided code templates for handling external string inputs.
Audit Metadata