salary-market-scanner

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple external websites, creating a surface for indirect prompt injection attacks.
  • Ingestion points: Data is fetched from Levels.fyi, Glassdoor, LinkedIn, and Indeed via the tinyfish agent run command in SKILL.md.
  • Boundary markers: None are explicitly used to separate the external data from the agent's instructions in the synthesis step.
  • Capability inventory: The skill executes shell commands (tinyfish, cat, echo, npm), writes to temporary files in /tmp, and performs network operations via sub-agents.
  • Sanitization: No sanitization or validation of the scraped content is performed before it is used to generate the final report.
  • [COMMAND_EXECUTION]: The skill uses shell commands to verify the environment, authenticate with the vendor platform, and execute scraping tasks using the tinyfish CLI tool.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the @tiny-fish/cli package from the npm registry and connects to various well-known job boards and salary databases to retrieve data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 01:41 AM
Security Audit — agent-trust-hub — salary-market-scanner