prospect-research
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its core function of ingesting and synthesizing untrusted data from LinkedIn profiles and the broader web. Malicious actors could potentially influence the agent's behavior by placing hidden instructions in their public-facing content.
- Ingestion points: LinkedIn profile information, approximately 50 recent posts, and various web-based search results (podcasts, articles, social media).
- Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands to separate untrusted data from the system prompt.
- Capability inventory: The agent is tasked with web research and scraping; the skill notes this is intended to be read-only.
- Sanitization: No explicit content filtering or sanitization steps are documented for the ingested external data.
- [EXTERNAL_DOWNLOADS]: The skill workflow involves multiple network operations to fetch data from LinkedIn and perform broad web searches across various third-party platforms (YouTube, X, Substack, Medium, etc.).
Audit Metadata