linkedin-micro-campaigns

Pass

Audited by Gen Agent Trust Hub on May 2, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill accesses sensitive CRM data including deals, contact job titles, and company information from HubSpot using authorized MCP tools. This data is used to define LinkedIn ad targeting. This behavior is documented as the skill's primary function and is performed within the user's authenticated environment.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests untrusted data from HubSpot CRM records (e.g., job titles or company names) which are then used to generate LinkedIn ad content.
  • Ingestion points: HubSpot CRM deal, contact, and company objects (SKILL.md, Step 1).
  • Boundary markers: None identified.
  • Capability inventory: Creation of LinkedIn campaign groups, campaigns, and ad creatives (SKILL.md, Steps 6-8).
  • Sanitization: None specified, but the risk is effectively mitigated by a mandatory user approval step (Step 5) and the fact that all created resources are set to a 'PAUSED' status (Step 7), preventing unauthorized ad spend or publication.
Audit Metadata
Risk Level
SAFE
Analyzed
May 2, 2026, 06:43 AM
Security Audit — agent-trust-hub — linkedin-micro-campaigns