competitor-post-engagers

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Detailed analysis of the skill's instructions and script logic shows it performs intended lead generation tasks without malicious intent.
  • [COMMAND_EXECUTION]: The skill executes a Python script to coordinate a multi-step data pipeline including scraping, ranking, and enrichment. The script uses standard libraries and workspace-internal utilities.
  • [DATA_EXFILTRATION]: User API tokens for Apify and Apollo are handled locally and passed to a vendor-owned proxy at app.gooseworks.ai. This domain belongs to the skill's author (gooseworks-ai) and is used for platform integration.
  • [EXTERNAL_DOWNLOADS]: The skill fetches external content from LinkedIn via Apify actors and retrieves company details from Apollo. These are well-known, trusted services in the context of lead generation.
  • [PROMPT_INJECTION]: The skill ingests LinkedIn comments, which are untrusted external data. This constitutes an indirect prompt injection surface if the agent later processes these comments for outreach. The implementation includes mitigation by truncating comment text to 500 characters and lacks any direct execution or logic-altering processing of the scraped text.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 03:06 PM
Security Audit — agent-trust-hub — competitor-post-engagers