AI Company HR

PassAudited by ClawScan on Apr 22, 2026.

Overview

An instruction-only HR orchestration skill whose declared permissions (file read/write, network API, subagent/session dispatch) and instructions align with its stated AI agent lifecycle management purpose, but it performs high-impact operations (knowledge sync, log archive, model-weight deletion, subagent dispatch) without technical detail—so proceed with caution and governance controls.

This skill appears internally consistent for managing AI-agent HR lifecycles, but it can perform high-impact operations (syncing knowledge vectors, archiving logs, deleting model weights, launching subagents) without technical detail about targets or safeguards. Before installing: 1) Ask where RAG/vector DB data will be sent and which endpoints are allowed; restrict network destinations to approved APIs. 2) Require an explicit human-approval gating policy (CLO/legal and HR) for any retirement/destruction operations; validate that 'Agent retirement requires human approval' is enforced, not just documented. 3) Limit mcp (subagent/session) privileges or audit their use; ensure subagents cannot exfiltrate sensitive data. 4) Ensure audit logging and an immutable record of actions and approvals exist. 5) If you rely on IBM AIF360/Fairlearn or other libs, provision them in a controlled environment rather than letting the skill fetch arbitrary code. These steps will reduce risk while keeping the skill usable.