hiring-intelligence

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves ingesting and analyzing data from external third-party platforms. This content is outside the agent's control and could contain malicious instructions (indirect prompt injection) designed to manipulate the analysis or output.
  • Ingestion points: External data retrieved from the job market and company search tools including linkedin_web_v2_search_jobs, linkedin_web_v2_job_detail, linkedin_web_v2_company_profile, apollo_company_job_postings, and apollo_company_search.
  • Boundary markers: Absent. The instructions do not specify any delimiters (like XML tags or triple quotes) to wrap external content, nor do they instruct the agent to ignore any potential commands found within the data.
  • Capability inventory: The agent has the capability to perform searches and retrieve detailed records from LinkedIn and Apollo. No direct shell or filesystem write capabilities are exposed in the provided skill definition.
  • Sanitization: Absent. There is no evidence of content filtering or validation of the external data before it is presented to the agent for synthesis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:30 PM
Security Audit — agent-trust-hub — hiring-intelligence