linkedin-carousels
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill's primary function is to provide structured instructions for designing LinkedIn carousel slides. It does not perform network operations or access sensitive system files.
- [COMMAND_EXECUTION]: A local shell script (
scripts/verify.sh) is included to lint the generated carousel specifications. It uses standard POSIX commands (grep,awk,find) for read-only static analysis of local markdown/text files. It does not exhibit behavior related to persistence or privilege escalation. - [PROMPT_INJECTION]: The skill includes instructions to process external source material (articles, blog posts) to create carousels. While this creates a surface for indirect prompt injection, the attack surface is minimal as the output is purely text-based design specifications.
- Ingestion points:
SKILL.md(source articles/posts provided by the user). - Boundary markers: Absent.
- Capability inventory: Text generation and read-only local script execution.
- Sanitization: Absent.
Audit Metadata