talent-sourcing

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process profile and company data from external sources, which could be leveraged to host malicious instructions intended to influence the agent's behavior.
  • Ingestion points: Data is retrieved from external platforms including LinkedIn (linkedin_web_v2_user_profile), GitHub (strale_github_user_profile), and Apollo (apollo_company_enrich) via the sandbase_call_tool function.
  • Boundary markers: Absent. The instructions do not provide delimiters or specific warnings to the agent to distinguish between its system instructions and the data fetched from external profile fields.
  • Capability inventory: The skill's capabilities are restricted to data retrieval through the SandBase gateway tools, and the instructions explicitly specify "Read-only research only. Never take actions on platforms" (SKILL.md).
  • Sanitization: Absent. There is no evidence of automated sanitization, validation, or filtering of the content retrieved from the external APIs before it enters the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — talent-sourcing