linkedin-outreach-campaign

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by ingesting untrusted user-generated content from LinkedIn comments and profile posts, which is then used to generate personalized outreach messages.
  • Ingestion points: Prospect data, including comment text and profile activity, is gathered via the linkedin-commenter-extractor and linkedin-profile-post-scraper skills.
  • Boundary markers: The instructions do not specify the use of delimiters or specific warnings for the agent to ignore potential instructions embedded within the processed comments during the message drafting phase.
  • Capability inventory: The skill possesses the capability to write to the local filesystem and log activity to an external database.
  • Sanitization: The skill does not mention specific sanitization, filtering, or validation steps for the external content before it is interpolated into message templates.
  • [DATA_EXFILTRATION]: The skill transmits outreach logs and prospect status to an external Supabase database. This is a core functionality for campaign management and, according to the instructions, occurs only after user approval for logging results from the tool-agnostic outreach capability.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 03:06 PM
Security Audit — agent-trust-hub — linkedin-outreach-campaign