influencer-post-engager-capture
Warn
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill incorporates unverified third-party dependencies via Apify actors (
apimaestroandharvestapi) as specified in SKILL.md and the setup checklist. These actors execute logic on external infrastructure to process user data and are not maintained by a verified organization, presenting a supply chain risk. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests untrusted LinkedIn post content and profile data to drive automated actions.
- Ingestion points: LinkedIn post body (Step 1), Engager headlines/profiles (Step 2, 3) in SKILL.md.
- Boundary markers: Absent. There are no instructions to the agent to treat scraped data as untrusted or to ignore embedded instructions within the LinkedIn content.
- Capability inventory: LinkedIn automated liking (Step 1b), Apify actor execution (Step 2, 3), Workspace/CRM search and data enrichment (Step 4, 5), Slack messaging (Step 6).
- Sanitization: Absent. Data from LinkedIn is directly interpolated into Slack messages and processed for automated decision-making regarding lead qualification.
Audit Metadata