Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from LinkedIn profiles and has capabilities to interact with the browser and file system.
- Ingestion points: Processes profile text, headlines, and 'About' sections retrieved via browser snapshots (
mcp__chrome-devtools__take_snapshot) and screenshots (mcp__chrome-devtools__take_screenshot) as described inSKILL.md. - Boundary markers: The skill lacks explicit instructions or delimiters to treat the ingested LinkedIn profile content as untrusted data or to ignore potential instructions embedded within it.
- Capability inventory: The skill uses MCP tools for browser interaction (
mcp__chrome-devtools__*,mcp__playwright__browser_*) and writes files to the local workspace (content/<platform>/drafts/) as defined inSKILL.md. - Sanitization: There is no evidence of content sanitization, validation, or filtering of the data retrieved from external browser pages before it is processed by the agent.
Audit Metadata