linkedin-automation
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires users to add an external MCP server endpoint (
https://rube.app/mcp) to their configuration. This server acts as a third-party dependency that provides the tool schemas and execution logic for the LinkedIn integration. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection by processing external data from LinkedIn profile and company records.
- Ingestion points: Data retrieved via
LINKEDIN_GET_MY_INFOandLINKEDIN_GET_COMPANY_INFOenters the agent context (SKILL.md). - Boundary markers: The instructions do not specify the use of delimiters or warnings to isolate external data from the agent's core instructions.
- Capability inventory: The skill utilizes tools with the ability to create posts (
LINKEDIN_CREATE_LINKED_IN_POST), post comments (LINKEDIN_CREATE_COMMENT_ON_POST), and delete content (LINKEDIN_DELETE_LINKED_IN_POST). - Sanitization: There is no mention of sanitization, validation, or filtering applied to the data ingested from LinkedIn before it is used to influence subsequent agent actions.
Audit Metadata