linkedin

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from LinkedIn profiles and has capabilities to interact with the browser and file system.
  • Ingestion points: Processes profile text, headlines, and 'About' sections retrieved via browser snapshots (mcp__chrome-devtools__take_snapshot) and screenshots (mcp__chrome-devtools__take_screenshot) as described in SKILL.md.
  • Boundary markers: The skill lacks explicit instructions or delimiters to treat the ingested LinkedIn profile content as untrusted data or to ignore potential instructions embedded within it.
  • Capability inventory: The skill uses MCP tools for browser interaction (mcp__chrome-devtools__*, mcp__playwright__browser_*) and writes files to the local workspace (content/<platform>/drafts/) as defined in SKILL.md.
  • Sanitization: There is no evidence of content sanitization, validation, or filtering of the data retrieved from external browser pages before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:07 PM
Security Audit — agent-trust-hub — linkedin