icp-to-linkedin-search

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies external website URLs as a primary source of information for defining a customer persona (ICP). It instructs the agent to visit specific pages (pricing, logos, docs) to extract data but does not provide safety guidelines or boundary markers to prevent the agent from being influenced by malicious instructions embedded in those external sites.
  • Ingestion points: External content is fetched and analyzed when a user provides a website URL (references/facets.md).
  • Boundary markers: The skill lacks explicit delimiters or "ignore embedded instructions" warnings for the agent when processing this external content.
  • Capability inventory: The skill is designed to transform text into structured boolean strings; it does not contain high-privilege capabilities like file writing or subprocess execution, but it does leverage the agent's web browsing capabilities.
  • Sanitization: No sanitization or validation logic is defined to filter out potentially malicious content from the retrieved web data.
  • [NO_CODE]: The skill consists entirely of markdown files (SKILL.md and reference files). It does not include any executable scripts, compiled binaries, or dependency management files (such as package.json or requirements.txt).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:55 AM
Security Audit — agent-trust-hub — icp-to-linkedin-search