li-comment
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [PERSISTENCE]: The skill instructs the agent to maintain a persistent log of interactions in
~/.claude/linkedin/log.md. This is used to track engagement history across different sessions to prevent repetitive commenting patterns. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data in the form of LinkedIn posts pasted by the user or read from screenshots.
- Ingestion points: Untrusted post text and author metadata are ingested as primary input in SKILL.md.
- Boundary markers: The skill lacks explicit delimiters or instructions for the agent to ignore potentially malicious commands embedded within the pasted LinkedIn content.
- Capability inventory: The agent is instructed to perform file-writing operations to a local log file (
~/.claude/linkedin/log.md) and utilize a formatting tool (/li-human). - Sanitization: There are no documented procedures for sanitizing or validating the input text before it is processed by the agent to generate comment options.
Audit Metadata