Juicebox Core Workflow ASAFE
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Overview
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
4f83675ca38aOBSERVED · 2026-10-09Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: juicebox-core-workflow-a description: 'Execute Juicebox people search with power filters and ATS export. Trigger: "find candidates", "people search", "juicebox search". ' allowed-tools: Read, Write, Edit, Bash(npm:*), Grep version: 1.16.0 license: MIT author: Jeremy Longshore <[email protected]> tags: - saas - recruiting - juicebox compatibility: Designed for Claude Code --- # Juicebox People Search Workflow ## Overview Complete candidate sourcing: natural language search with power filters, scoring, and export to 41+ ATS systems. ## Instructions ### Step 1: Power Filter Search ```typescript const results = await client.search({ query: 'backend engineer distributed systems', filters: { location: ['San Francisco', 'Seattle', 'Remote'], experience_years: { min: 3, max: 10 }, skills: ['Go', 'Kubernetes', 'distributed systems'], company_size: '100-1000', exclude_companies: ['CurrentEmployer'] }, sort: 'relevance', limit: 50 }); ``` ### Step 2: Score Candidates ```typescript function scoreCandidate(profile, targetSkills: string[]) { let score = 0; const matched = profile.skills.filter(s => targetSkills.some(t => s.toLowerCase().includes(t.toLowerCase())) ); score += matched.length * 20; if (profile.experience_years >= 5) score += 30; return { profile, score, matchedSkills: matched }; } const ranked = results.profiles .map(p => scoreCandidate(p, ['Go', 'Kubernetes'])) .sort((a, b) => b.score - a.score); ``` ### Step 3: Export to ATS ```typescript await client.export({ profiles: ranked.slice(0, 20).map(r => r.profile.id), destination: 'greenhouse', // lever, ashby, recruiterflow, etc. job_id: 'job_abc123' }); ``` ## Error Handling | Error | Cause | Solution | |-------|-------|----------| | Low results | Filters too strict | Relax experience or location | | Duplicates | Overlapping searches | Deduplicate by LinkedIn URL | ## Prerequisites - An approved hiring workflow, a sandbox workspace, documented source authority, a suppression list, and an allowlisted ATS test destination. ## Output Produce a redacted workflow receipt with the sandbox query scope, aggregate result count, suppression outcome, destination approval, `contacts_exported=0` test assertion, owner approval, retention window, and rollback reference. Do not retain candidate records, contact details, or credentials. ## Examples `workspace=sandbox-hiring; source=approved; query=synthetic-go-k8s; matched=20; suppression=pass; contacts_exported=0; retention=24h` is a valid pre-production receipt. ## Resources - Search Filters - [ATS Integrations](https://juicebox.ai/integrations) ## Next Steps For enrichment, see `juicebox-core-workflow-b`.
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__juicebox-core-workflow-a.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 4f83675ca38a | SAFE | B | 89 | first audit |
Questions
What does the Juicebox Core Workflow A skill do?
Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.
Is Juicebox Core Workflow A safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Juicebox Core Workflow A access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Juicebox Core Workflow A work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.