stalk-my-interviewer
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes shell control operators (parallel execution with
&and synchronization withwait) to manage multiple background research agents. It also performs local file operations, writing search results to the/tmpdirectory and aggregating them usingcat. - [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
@tiny-fish/clivia the Node Package Manager (npm). This is a vendor-supplied tool necessary for the skill to interact with the TinyFish agent platform. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from uncontrolled external sources, including social media bios, tweets, and search engine snippets.
- Ingestion points: Data is pulled into the agent's context from LinkedIn, GitHub, Twitter, and Google search results via the
tinyfishcommand-line tool inSKILL.md. - Boundary markers: The skill uses specific instructions and JSON formatting constraints within the agent prompts to guide data extraction, but lacks robust delimiters to isolate potentially adversarial text found on the web.
- Capability inventory: The skill possesses capabilities for network interaction (via the CLI), local filesystem writes (
/tmp), and command execution for task orchestration. - Sanitization: There is no evidence of specific sanitization or filtering logic applied to the external text before it is synthesized into the final preparation report.
Audit Metadata