skills/reggiechan74/jobops/findclient/Gen Agent Trust Hub

findclient

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes data from untrusted external sources.
  • Ingestion points: Web discovery results (Phase 3.1), LinkedIn profiles, Glassdoor reviews, and news articles (Phase 3.2).
  • Boundary markers: Absent. The skill does not instruct the agent to ignore instructions embedded in the external content.
  • Capability inventory: Local file reading (config and service definitions), web search, and local file writing (markdown reports).
  • Sanitization: Absent. Data from the web is parsed and directly incorporated into the scoring and reporting process.
  • [DATA_EXFILTRATION]: The skill transmits business criteria (industry names, pain points, service categories) to external search engines (Phase 2.1). This is a functional requirement of the discovery process and does not involve the transmission of sensitive user credentials, private files, or system environment data.
  • [COMMAND_EXECUTION]: The skill performs file system operations including reading from .jobops/config.json and writing reports to paths specified within that configuration. These operations are limited to the skill's defined workspace and follow standard patterns for tool-specific configuration management.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 11:42 AM
Security Audit — agent-trust-hub — findclient