linkedin

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Recommends installing the @membranehq/cli tool from the npm registry. This is the official CLI for the platform referenced in the skill metadata and homepage, developed by the vendor.
  • [COMMAND_EXECUTION]: Uses the membrane CLI to perform authentication, manage LinkedIn connections, and execute actions.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from LinkedIn, creating a surface for potential indirect instructions from external profiles or posts.
  • Ingestion points: Fetches external content via actions like list-posts, list-comments, and get-post described in SKILL.md.
  • Boundary markers: None explicitly mentioned in the skill instructions to delimit external content for the agent.
  • Capability inventory: The skill can modify external state through actions like create-post and delete-post via the membrane action run command in SKILL.md.
  • Sanitization: No specific sanitization or filtering logic is mentioned for processing data fetched from the API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 02:19 AM
Security Audit — agent-trust-hub — linkedin