Security audit
GitHub 人才猎手 (GitHub Talent Hunter)
Security checks for vulnerabilities and agentic risk
Overview
Prompt-injection indicators were detected in the submitted artifacts (unicode-control-chars); human review is required before treating this skill as clean.
Before installing, use a minimally scoped GitHub token, avoid committing any .env or data files, and understand that the skill will save candidate/search records locally. Review candidates and generated outreach manually, and delete local records when they are no longer needed. ClawScan detected prompt-injection indicators (unicode-control-chars), so this skill requires review even though the model response was benign.
Static analysis
No suspicious patterns detected.
