linkedin-outreach-campaign
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by ingesting untrusted user-generated content from LinkedIn comments and profile posts, which is then used to generate personalized outreach messages.
- Ingestion points: Prospect data, including comment text and profile activity, is gathered via the
linkedin-commenter-extractorandlinkedin-profile-post-scraperskills. - Boundary markers: The instructions do not specify the use of delimiters or specific warnings for the agent to ignore potential instructions embedded within the processed comments during the message drafting phase.
- Capability inventory: The skill possesses the capability to write to the local filesystem and log activity to an external database.
- Sanitization: The skill does not mention specific sanitization, filtering, or validation steps for the external content before it is interpolated into message templates.
- [DATA_EXFILTRATION]: The skill transmits outreach logs and prospect status to an external Supabase database. This is a core functionality for campaign management and, according to the instructions, occurs only after user approval for logging results from the tool-agnostic outreach capability.
Audit Metadata