linkedin-announcement-generator

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content from multiple local files which could contain adversarial instructions intended to influence the agent's behavior during text generation.
  • Ingestion points: The skill reads mkdocs.yml, docs/course-description.md, docs/learning-graph/book-metrics.md, and docs/learning-graph/chapter-metrics.md to extract metadata and statistics.
  • Boundary markers: There are no explicit instructions or delimiters provided to the agent to differentiate between data and potentially malicious commands within the source files.
  • Capability inventory: The skill utilizes file reading capabilities to populate social media templates and craft announcement variations.
  • Sanitization: The skill lacks validation or filtering mechanisms for the content extracted from the textbook documentation before it is interpolated into the final prompt context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:03 AM
Security Audit — agent-trust-hub — linkedin-announcement-generator