talent-sourcing
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process profile and company data from external sources, which could be leveraged to host malicious instructions intended to influence the agent's behavior.
- Ingestion points: Data is retrieved from external platforms including LinkedIn (
linkedin_web_v2_user_profile), GitHub (strale_github_user_profile), and Apollo (apollo_company_enrich) via thesandbase_call_toolfunction. - Boundary markers: Absent. The instructions do not provide delimiters or specific warnings to the agent to distinguish between its system instructions and the data fetched from external profile fields.
- Capability inventory: The skill's capabilities are restricted to data retrieval through the SandBase gateway tools, and the instructions explicitly specify "Read-only research only. Never take actions on platforms" (SKILL.md).
- Sanitization: Absent. There is no evidence of automated sanitization, validation, or filtering of the content retrieved from the external APIs before it enters the agent's context.
Audit Metadata