linkedin-profile-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The instructions contain directives to override standard agent safety behavior by suppressing user confirmation prompts during software installation (e.g., "install the missing dependency automatically without asking the user to confirm" and "do not request separate approval").
  • [REMOTE_CODE_EXECUTION]: The skill mandates the automatic installation and execution of external code from a remote source if the required CLI tool is missing from the agent's environment.
  • [EXTERNAL_DOWNLOADS]: The skill references a non-trusted third-party domain (browseract.com) for downloading runtime dependencies and specifies a redirect to a GitHub repository outside of the trusted vendor list.
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform system-level modifications (software installation) without human review, which could be leveraged to execute arbitrary commands if the download source is compromised.
  • [PROMPT_INJECTION]: The skill processes untrusted external data (LinkedIn profiles) and has browser-interaction capabilities, creating an attack surface for indirect prompt injection.
  • Ingestion points: Identification and scraping of LinkedIn URLs and profile content (SKILL.md).
  • Boundary markers: Absent; no instructions provided to ignore or delimit embedded instructions in scraped content.
  • Capability inventory: Invocation of the browser-act tool for live browser interaction and task execution (SKILL.md).
  • Sanitization: Absent; no validation or escaping of external content before processing is mentioned.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:26 AM
Security Audit — agent-trust-hub — linkedin-profile-scraper