company-hiring-intelligence
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on executing the
tinyfishCLI tool to conduct web scraping and browser automation.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external career sites, LinkedIn, and engineering blogs, creating a surface for potential indirect prompt injection attacks.\n - Ingestion points: Data extracted from external websites using the
tinyfish agent runcommand.\n - Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the scraped content.\n
- Capability inventory: The agent possesses shell execution capabilities (via the CLI) and file system access (writing to
/tmp/).\n - Sanitization: No sanitization or validation of the ingested JSON data is specified before the final analysis and synthesis step.
Audit Metadata