linkedin-research
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes data from external sources (LinkedIn), which could theoretically contain instructions designed to manipulate the agent's output or behavior.
- Ingestion points: The skill ingests untrusted data from LinkedIn company profiles, user profiles, posts, comments, and job descriptions via the
linkedin_web_v2_*tools described inSKILL.mdandreferences/sandbase-api-map.md. - Boundary markers: Absent. The instructions do not define clear delimiters or specific instructions for the agent to ignore embedded commands within the fetched LinkedIn data.
- Capability inventory: The skill uses
sandbase_call_toolandsandbase_describe_toolto interact with the SandBase API gateway. No local file-writing, command execution, or other high-privilege capabilities were detected. - Sanitization: Absent. The skill does not specify any sanitization, filtering, or validation of the content returned from the API before it is presented to the agent context.
Audit Metadata