linkedin-outreach

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it instructs the agent to ingest and act upon untrusted data from external LinkedIn profiles and user-generated posts.
  • Ingestion points: External data enters the agent context during the "Target", "Warm", and "Convert" phases (SKILL.md) when the agent is directed to read profile details, post content, and comments.
  • Boundary markers: The instructions lack explicit delimiters or instructions to treat external data strictly as data, which could allow malicious instructions embedded in a target's profile or post to influence agent behavior.
  • Capability inventory: The agent has the capability to write to a local file (02-DOCS/linkedin-outreach/touches.csv) and execute a local shell script (scripts/verify.sh) for data validation.
  • Sanitization: While scripts/verify.sh checks for placeholder tokens, it does not sanitize or filter external content for potential prompt injection strings before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — linkedin-outreach