linkedin-cta
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install the @coldiq/mcp package from the NPM registry to enable advanced social intelligence features.\n- [REMOTE_CODE_EXECUTION]: The documentation includes a setup command (npx -y @coldiq/mcp@latest) that downloads and executes code from a remote registry to initialize the MCP environment.\n- [PROMPT_INJECTION]: The skill is configured to ingest external social media data, creating a surface for potential indirect prompt injection.\n
- Ingestion points: Processes LinkedIn post engagement data through the mcp__coldiq__extract_post_engagement tool in SKILL.md.\n
- Boundary markers: The skill does not explicitly define delimiters to isolate external engagement data from its core instructions.\n
- Capability inventory: The skill's actions are restricted to designing marketing copy, CTAs, and profile optimization strategies.\n
- Sanitization: No specific input validation or sanitization routines are mentioned for the external engagement data retrieved.
Audit Metadata