research-linkedin
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes browser automation and git commands (
commit,push) to collect and synchronize data. These operations are essential to its documented functionality and are gated by explicit user confirmation steps. - [PROMPT_INJECTION]: The skill ingests untrusted data from LinkedIn, creating an indirect prompt injection surface. * Ingestion points: LinkedIn profile activity posts and thesis statements from external profiles. * Boundary markers: None identified in the provided instructions. * Capability inventory: File-write permissions for
signals-data.jsonandsocial_scan_manifest.json, along with network access via browser automation and git. * Sanitization: No explicit sanitization or content validation for the scraped LinkedIn data is specified. - [SAFE]: The skill incorporates critical safety controls, including a requirement for the user to be physically present and to provide explicit confirmation before the automation begins.
Audit Metadata