li-comment

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PERSISTENCE]: The skill instructs the agent to maintain a persistent log of interactions in ~/.claude/linkedin/log.md. This is used to track engagement history across different sessions to prevent repetitive commenting patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data in the form of LinkedIn posts pasted by the user or read from screenshots.
  • Ingestion points: Untrusted post text and author metadata are ingested as primary input in SKILL.md.
  • Boundary markers: The skill lacks explicit delimiters or instructions for the agent to ignore potentially malicious commands embedded within the pasted LinkedIn content.
  • Capability inventory: The agent is instructed to perform file-writing operations to a local log file (~/.claude/linkedin/log.md) and utilize a formatting tool (/li-human).
  • Sanitization: There are no documented procedures for sanitizing or validating the input text before it is processed by the agent to generate comment options.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 05:51 PM