kol-discovery

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: Executes a Python script to automate the aggregation, scoring, and ranking of Key Opinion Leaders (KOLs) based on engagement metrics.
  • [EXTERNAL_DOWNLOADS]: Fetches data from the LinkedIn post search service via the vendor's official API proxy at app.gooseworks.ai.
  • [CREDENTIALS_UNSAFE]: Accesses the GOOSEWORKS_API_KEY and APIFY_API_TOKEN from the execution environment to facilitate authorized requests to the search service.
  • [PROMPT_INJECTION]: Processes external content from LinkedIn posts as part of its discovery workflow; while this introduces a theoretical surface for indirect prompt injection, the risk is mitigated by content truncation to 100-200 characters.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 03:06 PM
Security Audit — agent-trust-hub — kol-discovery