connections-optimizer

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data from external social media profiles (X and LinkedIn) to rank connections and identify outreach paths. This creates a surface for indirect prompt injection where malicious instructions in a profile could influence agent behavior.
  • Ingestion points: Connection inventory and activity data retrieved from X and LinkedIn via API or browser automation.
  • Boundary markers: The instructions do not specify any delimiters or safety markers to isolate external profile content from the agent's core instructions.
  • Capability inventory: The agent has the ability to draft messages across multiple platforms (X, LinkedIn, Apple Mail) and initiate account pruning actions.
  • Sanitization: No explicit sanitization or filtering of external data is defined before processing.
  • [NO_CODE]: The skill consists exclusively of markdown instructions and does not include any companion scripts, executables, or code files. All logic is handled through natural language instructions to the agent.
  • [SAFE]: The skill implements strong safety defaults, explicitly requiring a "review-first" approach and prohibiting the automatic sending of messages or blind pruning of accounts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 12:57 PM
Security Audit — agent-trust-hub — connections-optimizer