influencer-post-engager-capture

Warn

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill incorporates unverified third-party dependencies via Apify actors (apimaestro and harvestapi) as specified in SKILL.md and the setup checklist. These actors execute logic on external infrastructure to process user data and are not maintained by a verified organization, presenting a supply chain risk.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests untrusted LinkedIn post content and profile data to drive automated actions.
  • Ingestion points: LinkedIn post body (Step 1), Engager headlines/profiles (Step 2, 3) in SKILL.md.
  • Boundary markers: Absent. There are no instructions to the agent to treat scraped data as untrusted or to ignore embedded instructions within the LinkedIn content.
  • Capability inventory: LinkedIn automated liking (Step 1b), Apify actor execution (Step 2, 3), Workspace/CRM search and data enrichment (Step 4, 5), Slack messaging (Step 6).
  • Sanitization: Absent. Data from LinkedIn is directly interpolated into Slack messages and processed for automated decision-making regarding lead qualification.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 28, 2026, 04:39 PM
Security Audit — agent-trust-hub — influencer-post-engager-capture