hiring-rubric-author

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional markdown and configuration files. No executable scripts, binary files, or automated command-line instructions were detected.
  • [SAFE]: All external references are to well-known documentation sources and educational resources, such as Wikipedia, ISTQB, and industry reports. These are used for contextual reference and do not involve remote code execution or data exfiltration.
  • [PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection by instructing the agent to process external data.
  • Ingestion points: The workflow requires a "Role + seniority" description, a "Question bank", and an optional "Team's competency model" as inputs in SKILL.md.
  • Boundary markers: Absent; the instructions do not specify the use of delimiters or warnings to ignore embedded instructions within the ingested data.
  • Capability inventory: None; the skill's functionality is limited to generating text-based markdown output and does not invoke any system tools, network operations, or file-writing capabilities.
  • Sanitization: Absent; no validation or escaping of the input data is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 11:00 AM
Security Audit — agent-trust-hub — hiring-rubric-author