linkedin-dm-signal-classifier

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from LinkedIn DMs and uses this content to perform classification (Step 5) and lead scoring (Step 6.5). An attacker could potentially craft a message designed to influence these automated classifications or trigger specific routing actions.
  • Ingestion points: Untrusted message content is fetched from LinkedIn chats in Step 2 and Step 3.
  • Boundary markers: The skill requires quoting messages verbatim in blockquotes for Slack posts, but does not specify delimiters or sanitization for the internal context used during classification.
  • Capability inventory: The skill possesses the capability to write to the CRM, update account memory, and initiate outreach sequences (though these are queued for approval).
  • Sanitization: No explicit sanitization or filtering of DM content is mentioned prior to processing.
  • [DATA_EXFILTRATION]: The skill's primary function involves the extraction of private communications and PII (names, titles, LinkedIn URLs, and potentially emails) from the LinkedIn platform and exporting this data to external services including Slack and the user's CRM. While this is the intended purpose, it constitutes a movement of sensitive data to external endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 04:39 PM
Security Audit — agent-trust-hub — linkedin-dm-signal-classifier