job-market-intel

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external job postings which may contain malicious instructions targeting the LLM.
  • Ingestion points: Job listing descriptions and snippets retrieved from LinkedIn, Indeed, and Glassdoor via the tinyfish agent run command in SKILL.md.
  • Boundary markers: Absent; the instructions do not provide specific delimiters or warnings to the agent to disregard instructions found within the job listing text.
  • Capability inventory: The agent can execute CLI commands (tinyfish), synthesize data into reports, and store results in local files.
  • Sanitization: Absent; no explicit sanitization or filtering of the job posting content is performed before the agent processes and synthesizes the data.
  • [COMMAND_EXECUTION]: The skill provides numerous examples for executing shell commands and managing system environments.
  • Evidence: The skill uses tinyfish agent run for its core functionality and provides commands for platform-specific task automation using Start-Job (PowerShell) and background processes (bash/zsh).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 08:41 AM
Security Audit — agent-trust-hub — job-market-intel