hiring-intelligence
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves ingesting and analyzing data from external third-party platforms. This content is outside the agent's control and could contain malicious instructions (indirect prompt injection) designed to manipulate the analysis or output.
- Ingestion points: External data retrieved from the job market and company search tools including
linkedin_web_v2_search_jobs,linkedin_web_v2_job_detail,linkedin_web_v2_company_profile,apollo_company_job_postings, andapollo_company_search. - Boundary markers: Absent. The instructions do not specify any delimiters (like XML tags or triple quotes) to wrap external content, nor do they instruct the agent to ignore any potential commands found within the data.
- Capability inventory: The agent has the capability to perform searches and retrieve detailed records from LinkedIn and Apollo. No direct shell or filesystem write capabilities are exposed in the provided skill definition.
- Sanitization: Absent. There is no evidence of content filtering or validation of the external data before it is presented to the agent for synthesis.
Audit Metadata