linkedin-automation

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires users to add an external MCP server endpoint (https://rube.app/mcp) to their configuration. This server acts as a third-party dependency that provides the tool schemas and execution logic for the LinkedIn integration.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection by processing external data from LinkedIn profile and company records.
  • Ingestion points: Data retrieved via LINKEDIN_GET_MY_INFO and LINKEDIN_GET_COMPANY_INFO enters the agent context (SKILL.md).
  • Boundary markers: The instructions do not specify the use of delimiters or warnings to isolate external data from the agent's core instructions.
  • Capability inventory: The skill utilizes tools with the ability to create posts (LINKEDIN_CREATE_LINKED_IN_POST), post comments (LINKEDIN_CREATE_COMMENT_ON_POST), and delete content (LINKEDIN_DELETE_LINKED_IN_POST).
  • Sanitization: There is no mention of sanitization, validation, or filtering applied to the data ingested from LinkedIn before it is used to influence subsequent agent actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 01:18 PM