research-linkedin

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes browser automation and git commands (commit, push) to collect and synchronize data. These operations are essential to its documented functionality and are gated by explicit user confirmation steps.
  • [PROMPT_INJECTION]: The skill ingests untrusted data from LinkedIn, creating an indirect prompt injection surface. * Ingestion points: LinkedIn profile activity posts and thesis statements from external profiles. * Boundary markers: None identified in the provided instructions. * Capability inventory: File-write permissions for signals-data.json and social_scan_manifest.json, along with network access via browser automation and git. * Sanitization: No explicit sanitization or content validation for the scraped LinkedIn data is specified.
  • [SAFE]: The skill incorporates critical safety controls, including a requirement for the user to be physically present and to provide explicit confirmation before the automation begins.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 05:12 PM
Security Audit — agent-trust-hub — research-linkedin