stalk-my-interviewer

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes shell control operators (parallel execution with & and synchronization with wait) to manage multiple background research agents. It also performs local file operations, writing search results to the /tmp directory and aggregating them using cat.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @tiny-fish/cli via the Node Package Manager (npm). This is a vendor-supplied tool necessary for the skill to interact with the TinyFish agent platform.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from uncontrolled external sources, including social media bios, tweets, and search engine snippets.
  • Ingestion points: Data is pulled into the agent's context from LinkedIn, GitHub, Twitter, and Google search results via the tinyfish command-line tool in SKILL.md.
  • Boundary markers: The skill uses specific instructions and JSON formatting constraints within the agent prompts to guide data extraction, but lacks robust delimiters to isolate potentially adversarial text found on the web.
  • Capability inventory: The skill possesses capabilities for network interaction (via the CLI), local filesystem writes (/tmp), and command execution for task orchestration.
  • Sanitization: There is no evidence of specific sanitization or filtering logic applied to the external text before it is synthesized into the final preparation report.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 01:04 AM
Security Audit — agent-trust-hub — stalk-my-interviewer