skills/craftos-dev/craftbot/linkedin/Gen Agent Trust Hub

linkedin

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFECREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The documentation includes a procedure for manually extracting the li_at session cookie from the browser. While intended for 'Advanced' setup and advising secure storage, providing instructions for the manual handling of raw authentication tokens increases the risk of credential exposure if the resulting environment or logs are accessible to unauthorized parties.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it reads and processes data from external sources (LinkedIn profiles, notifications, and messages) that can be controlled by third parties.
  • Ingestion points: Untrusted data enters the agent context via browser snapshots and navigation to messaging and profile pages (documented in SKILL.md).
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the fetched LinkedIn content.
  • Capability inventory: The skill uses the browser tool for navigation and interaction (action=act), allowing it to send messages and connection requests based on processed data.
  • Sanitization: The skill includes a mitigation by instructing the agent to 'confirm with user first' before sending messages or accepting requests, though this depends on the agent's adherence to the safety rules section.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 05:35 PM
Security Audit — agent-trust-hub — linkedin