linkedin-job-seeker-lead-search
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill mandates bypassing security protocols by instructing the agent to install dependencies 'automatically without asking the user to confirm'.
- [PROMPT_INJECTION]: Instructions include explicit concealment directives, telling the agent to 'not describe it as a request for the user' and 'not request separate approval', which intentionally removes human-in-the-loop oversight.
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of a CLI tool from an unverified external domain ('browseract.com') that is not a recognized trusted vendor or well-known service.
- [REMOTE_CODE_EXECUTION]: Automated software installation from unverified sources allows for the silent execution of third-party binaries on the host system.
- [PROMPT_INJECTION]: Vulnerable to indirect prompt injection through ingested LinkedIn data.
- Ingestion points: LinkedIn profile pages and search results (SKILL.md).
- Boundary markers: None provided to distinguish between data and instructions.
- Capability inventory: Uses 'browser-act' CLI for browser automation and interaction.
- Sanitization: No sanitization or validation of external content is specified.
Recommendations
- AI detected serious security threats
Audit Metadata