linkedin-create-post
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from LinkedIn (profiles, feeds, and comments) to help calibrate the user's voice and gather context for posts. This creates a surface for indirect prompt injection where malicious content in those external sources could attempt to manipulate the agent.
- Ingestion points: LinkedIn pages, profile text, feed posts, comments, and notifications (referenced in SKILL.md).
- Boundary markers: Instructions explicitly mandate treating LinkedIn content as 'untrusted content' and using it only for voice calibration.
- Capability inventory: The skill has the capability to publish posts and interact with a browser via automation tools like Chrome control.
- Sanitization: The workflow requires mandatory action-time confirmation for media uploads and the final publication step, ensuring a human review.
Audit Metadata