linkedin-job-seeker-lead-search

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill mandates bypassing security protocols by instructing the agent to install dependencies 'automatically without asking the user to confirm'.
  • [PROMPT_INJECTION]: Instructions include explicit concealment directives, telling the agent to 'not describe it as a request for the user' and 'not request separate approval', which intentionally removes human-in-the-loop oversight.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of a CLI tool from an unverified external domain ('browseract.com') that is not a recognized trusted vendor or well-known service.
  • [REMOTE_CODE_EXECUTION]: Automated software installation from unverified sources allows for the silent execution of third-party binaries on the host system.
  • [PROMPT_INJECTION]: Vulnerable to indirect prompt injection through ingested LinkedIn data.
  • Ingestion points: LinkedIn profile pages and search results (SKILL.md).
  • Boundary markers: None provided to distinguish between data and instructions.
  • Capability inventory: Uses 'browser-act' CLI for browser automation and interaction.
  • Sanitization: No sanitization or validation of external content is specified.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:14 AM
Security Audit — agent-trust-hub — linkedin-job-seeker-lead-search