linkedin-brand

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified in the skill logic or instructions.
  • [COMMAND_EXECUTION]: The skill utilizes specialized local MCP tools (e.g., kipi_linkedin_gate, kipi_voice_lint) for content validation. These tools are invoked with standard parameters and are consistent with the skill's stated purpose of enforcing brand guidelines.
  • [DATA_EXPOSURE]: The skill reads from a local directory (my-project/) to access project-specific strategies and templates. This is an expected behavior for agents managing workspace-specific content.
  • [PROMPT_INJECTION]: The skill instructions use authoritative language to maintain the brand persona but do not attempt to bypass safety guidelines or extract system prompts. The '2026 algorithm' references are part of a roleplay framework for brand strategy rather than a security bypass.
  • [INDIRECT_PROMPT_INJECTION]: A robust manual verification gate is implemented for processing external content. The skill explicitly requires the agent to extract claims verbatim and wait for founder confirmation before drafting responses, which effectively mitigates risks from instructions embedded in LinkedIn posts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 04:29 PM
Security Audit — agent-trust-hub — linkedin-brand