employer-footprint

Pass

Audited by Gen Agent Trust Hub on Mar 25, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface area for indirect prompt injection because it ingests and processes untrusted data from external sources.
  • Ingestion points: WebSearch results from platforms like LinkedIn, Twitter/X, and GitHub, as well as user-provided CV content (referenced in references/digital-footprint-audit.md and SKILL.md).
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands were found in the prompts directing the research agents.
  • Capability inventory: The skill possesses the ability to write files to the local workspace ({name-slug}-footprint-dashboard.md).
  • Sanitization: No explicit sanitization or validation of the ingested web content or CV data is mentioned before it is synthesized into the final report.
  • [DATA_EXFILTRATION]: The skill handles sensitive Personally Identifiable Information (PII), including full names, career history (CV), and social media profiles. The analysis shows this data is processed locally to generate markdown reports for the user and is not transmitted to unauthorized third-party servers beyond the use of standard web search and fetch tools.
  • [COMMAND_EXECUTION]: The skill uses parallel Task tool calls to orchestrate research agents. These operations are limited to search and analysis tasks and do not involve arbitrary shell command execution or privilege escalation patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 25, 2026, 07:04 PM
Security Audit — agent-trust-hub — employer-footprint