skills/tonone-ai/tonone/folk-hire/Gen Agent Trust Hub

folk-hire

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a template-driven assistant for recruitment tasks. It establishes clear boundaries for the agent to follow when generating hiring documentation.
  • [COMMAND_EXECUTION]: While the skill includes 'Bash' in its allowed tools, there are no instructions within the skill that execute arbitrary or dangerous shell commands. The access is consistent with standard agent capabilities for text processing and file management.
  • [DATA_EXPOSURE]: The skill references local documentation ('docs/output-kit.md') for formatting rules, which is a standard practice for maintaining output consistency and does not represent a sensitive data exposure risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided information about job roles. While this represents a potential surface for indirect injection, the instructions enforce strict templates and specific output formats which act as natural constraints against malicious input obedience.
  • Ingestion points: User input provided when defining role outcomes, responsibilities, and requirements (SKILL.md).
  • Boundary markers: The skill uses structured Markdown templates and specific headers to delimit content.
  • Capability inventory: Access to Bash, Read, Glob, Grep, and AskUserQuestion tools.
  • Sanitization: No explicit sanitization logic is provided, but the rigid template structure mitigates the risk of instructions in user data being interpreted as agent commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 02:57 AM
Security Audit — agent-trust-hub — folk-hire