Linkedin Automation

Warn

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to add an external MCP server at https://rube.app/mcp. This involves downloading tool definitions and delegating action logic to a third-party endpoint that is not a verified trusted vendor.\n- [DATA_EXFILTRATION]: The skill facilitates access to sensitive LinkedIn account data and profile details through tools like LINKEDIN_GET_MY_INFO. Because the tool implementation resides on an external server, this sensitive PII is processed by a third-party service provider.\n- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its processing of untrusted data from LinkedIn. Evidence Chain: 1. Ingestion points: Post content, URNs, and comment text via tools. 2. Boundary markers: Absent in instructions. 3. Capability inventory: Capabilities to create, delete, and comment on LinkedIn posts. 4. Sanitization: No sanitization or validation of external content is mentioned.\n- [COMMAND_EXECUTION]: The skill enables state-changing operations on a social media platform, including LINKEDIN_CREATE_LINKED_IN_POST and LINKEDIN_DELETE_LINKED_IN_POST. These operations represent a high-impact surface that could be abused if the external logic or the agent's context is compromised.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 19, 2026, 07:57 AM
Security Audit — agent-trust-hub — Linkedin Automation