kol-engager-icp
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill triggers the execution of external Apify actors via a vendor-provided API proxy at app.gooseworks.ai to perform LinkedIn data scraping.
- [DATA_EXFILTRATION]: The script fetches LinkedIn profile data and engagement information and saves it to local files in the configs/ and output/ directories as part of its core functionality.
- [PROMPT_INJECTION]: The skill ingests untrusted text from LinkedIn headlines and comments. Ingestion points: Profile and comment data fetched via Apify. Boundary markers: Not present in processing scripts. Capability inventory: File writing and network access to vendor infrastructure. Sanitization: None; data is processed as strings for classification.
Audit Metadata