linkedin-strategy

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to execute a local bash script (scripts/verify.sh) to perform structural validation on decision records. The script conducts read-only operations using grep and sed to verify that required fields (like dates and metrics) are present in the generated Markdown files. While this involves shell execution, the script is part of the skill package and operates on specific local directories.\n- [INDIRECT_PROMPT_INJECTION]: The skill operates on a read/write loop with a local wiki (02-DOCS/wiki/linkedin/). This creates an attack surface where malicious or conflicting instructions embedded in the wiki files could influence the agent's strategic outputs.\n
  • Ingestion points: The skill reads positioning data, content pillars, and historical metrics from Markdown files within the 02-DOCS/wiki/linkedin/ directory (SKILL.md, Section 1).\n
  • Boundary markers: There are no explicit instructions or delimiters defined to isolate ingested wiki content from the agent's core instructions, making it potentially susceptible to embedded commands.\n
  • Capability inventory: The skill has the capability to write files to the local filesystem and execute the verify.sh shell script (SKILL.md, Section 7).\n
  • Sanitization: The skill does not perform specific sanitization or filtering on the text extracted from the wiki before using it to generate new decision records.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:57 AM
Security Audit — agent-trust-hub — linkedin-strategy