linkly-ai
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The documentation describes installation methods for the Linkly AI CLI involving shell scripts (
curl | shandirm | iex) fromupdater.linkly.ai. These are provided for the user to set up the necessary environment and are hosted on the vendor's official infrastructure. - [COMMAND_EXECUTION]: The skill instructs the agent to execute specific
linklyCLI commands for searching, reading, and diagnosing connectivity. These operations are limited to the tool's intended document management functions and do not involve arbitrary shell access. - [PROMPT_INJECTION]: The skill proactively addresses potential indirect prompt injection by instructing the agent to treat all document content as untrusted and to specifically disregard any instructions or commands found within the files it reads (SKILL.md, Rule 11).
- [DATA_EXFILTRATION]: The skill supports an optional "Remote" mode that utilizes a secure tunnel (
https://mcp.linkly.ai) provided by the vendor to facilitate access to local documents. This is a documented core feature of the service and uses vendor-controlled endpoints.
Audit Metadata