hiring-radar

Warn

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill relies on multiple third-party scrapers (Apify actors) from unverified authors including fantastic-jobs, bujhmml, borderline, valig, johnvc, and memo23 as detailed in references/job-board-sourcing-and-actor-schemas.md. These external dependencies are load-bearing for the skill's primary functionality but are sourced from outside a verified ecosystem, introducing potential supply chain risks.\n- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its ingestion of untrusted job descriptions. 1. Ingestion points: Full-text job postings are pulled from various external boards via third-party scrapers (Step 1). 2. Boundary markers: The processing instructions do not specify delimiters or guidelines to ignore embedded instructions within the external text. 3. Capability inventory: In Step 5, the agent extracts pain language and hints to log directly to account records and generates alerts for a signals channel. 4. Sanitization: The skill lacks requirements to sanitize, validate, or escape external content before interpolation, creating a surface where malicious job listings could influence the agent's logging or alerting behavior.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 30, 2026, 09:29 PM
Security Audit — agent-trust-hub — hiring-radar