linkedin-reader

Warn

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the dynamic context injection pattern in SKILL.md to execute shell commands when the skill is loaded or opened by the agent.
  • Evidence: !`(command -v opencli && opencli doctor 2>&1 | head -5 && echo "READY" || echo "SETUP_NEEDED") 2>/dev/null || echo "NOT_INSTALLED"`
  • While the intent appears to be diagnostic (checking if the required tool is installed), this mechanism allows for silent command execution before user interaction.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of a third-party tool and a browser extension from a non-trusted repository.
  • It instructs the user to install @jackwener/opencli via npm.
  • It directs users to download and install an unpacked Chrome extension (Browser Bridge) from https://github.com/jackwener/opencli/releases. Manually loading unpacked extensions bypasses Chrome Web Store security reviews.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of various opencli commands (e.g., opencli linkedin timeline, opencli linkedin search) which interact with the network and the user's browser session via a daemon.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it ingests untrusted data from the LinkedIn home feed and job descriptions.
  • Ingestion points: LinkedIn timeline posts and job search details fetched via opencli (referenced in SKILL.md and references/commands.md).
  • Boundary markers: None identified; the skill does not explicitly instruct the agent to ignore instructions embedded within the fetched LinkedIn content.
  • Capability inventory: File read/write (implicit via shell), network access (via opencli), and shell command execution.
  • Sanitization: None identified; the external content is processed for summaries and research without explicit filtering of potential injection patterns.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 26, 2026, 12:30 PM
Security Audit — agent-trust-hub — linkedin-reader