interview-prep

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local shell commands using the tinyfish CLI to perform web scraping, check authentication status, and manage temporary data files.
  • Evidence includes calls to tinyfish agent run, tinyfish auth status, and shell operations like cat, wait, and output redirection to /tmp.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes content from public websites which may contain user-generated instructions intended to influence the agent.
  • Ingestion points: The skill retrieves data from search results and review pages on Glassdoor, Blind, and Reddit.
  • Boundary markers: The instructions for the scraping agents include specific constraints such as "5 cards maximum", "Do NOT click any card", and "Read only the top-level post text" to limit the scope of ingested data.
  • Capability inventory: The skill has the ability to execute shell commands and perform network operations via the TinyFish tool.
  • Sanitization: The scraped data is processed by an LLM to synthesize a prep guide, but there is no explicit sanitization or escaping of the raw strings retrieved from the web.
  • [EXTERNAL_DOWNLOADS]: The skill documentation instructs the user to install the tinyfish package from the official npm registry and references the TinyFish cookbook repository on GitHub.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:29 PM
Security Audit — agent-trust-hub — interview-prep