recruiting-pipeline
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- Indirect Prompt Injection Surface: The skill is intended to manage and pull data from candidate pipelines and Applicant Tracking Systems (ATS). Processing external candidate-provided content, such as resumes or profiles, introduces a potential surface for indirect prompt injection where malicious instructions embedded in that data could attempt to influence the agent's actions.
- Ingestion points: Candidate data pulled from connected ATS or provided during sourcing.
- Boundary markers: No specific delimiters or safety instructions are defined to separate candidate data from system instructions.
- Capability inventory: While no executable code is present in this skill, the agent's underlying tools for data processing and status updates are the intended execution environment.
- Sanitization: The skill does not specify any sanitization or validation steps for the external data it processes.
Audit Metadata