workorai

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses a remote MCP server for all functional operations, ensuring no unauthorized local code execution occurs. The transport is secured over HTTPS.
  • [EXTERNAL_DOWNLOADS]: Mentions the official WorkorAI NPM package and GitHub repository as resources for integration and setup.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests marketplace data such as job descriptions and candidate profiles. The ingestion point is the MCP tool output from the WorkorAI API. The skill mitigates risks associated with untrusted content by requiring explicit user confirmation for all stateful marketplace actions and by strictly defining the scope of available tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 09:42 PM
Security Audit — agent-trust-hub — workorai