linkedin-outbound-angle

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were identified in the skill's instructions or logic.
  • [DATA_EXFILTRATION]: The skill uses the web_fetch tool to retrieve profile information from LinkedIn, which is a well-known service. This behavior is essential to its stated purpose and does not involve accessing sensitive local files or credentials.
  • [PROMPT_INJECTION]: The skill processes external data from LinkedIn profiles, which presents an indirect prompt injection surface. (1) Ingestion points: LinkedIn profile data (URLs, screenshots, or text) as defined in Phase 2. (2) Boundary markers: Absent; there are no explicit delimiters to separate profile content from the agent's instructions. (3) Capability inventory: The skill is limited to text generation and does not have access to file-writing, subprocess execution, or unauthorized network tools. (4) Sanitization: Absent; the skill does not explicitly sanitize the external content. Because the skill lacks dangerous capabilities, the risk associated with processing external content is restricted to the generated text output and does not pose a system security threat.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 02:22 PM
Security Audit — agent-trust-hub — linkedin-outbound-angle