hiring-rubric-author
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill consists entirely of instructional markdown and configuration files. No executable scripts, binary files, or automated command-line instructions were detected.
- [SAFE]: All external references are to well-known documentation sources and educational resources, such as Wikipedia, ISTQB, and industry reports. These are used for contextual reference and do not involve remote code execution or data exfiltration.
- [PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection by instructing the agent to process external data.
- Ingestion points: The workflow requires a "Role + seniority" description, a "Question bank", and an optional "Team's competency model" as inputs in SKILL.md.
- Boundary markers: Absent; the instructions do not specify the use of delimiters or warnings to ignore embedded instructions within the ingested data.
- Capability inventory: None; the skill's functionality is limited to generating text-based markdown output and does not invoke any system tools, network operations, or file-writing capabilities.
- Sanitization: Absent; no validation or escaping of the input data is defined.
Audit Metadata