hiring-signal-prospecting
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates by analyzing external job postings, which creates a surface for indirect prompt injection attacks where malicious instructions could be embedded in the source text. Ingestion points: External job descriptions and LinkedIn company pages are used as data sources (SKILL.md, reading-the-posting.md). Boundary markers: The skill does not define boundary markers or instruct the agent to ignore instructions embedded in the external text. Capability inventory: The skill identifies targets for outreach but lacks automated execution capabilities such as file system access or network requests. Sanitization: There is no evidence of sanitization or filtering applied to the external text before processing.
Audit Metadata