linkedin-account-research
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [SAFE]: A detailed analysis of the skill's instructions, metadata, and workflow confirmed that the agent's operations are limited to read-only research and information synthesis. No evidence of malicious intent, obfuscation, or unauthorized access to sensitive files was found.
- [EXTERNAL_DOWNLOADS]: The skill utilizes an external MCP server hosted at
mcp.unifapi.comand references installation via theunifapi-agent/agentspackage. These resources are managed by the skill's author and are used for their intended purpose of providing live data access. - [PROMPT_INJECTION]: The skill ingests untrusted data from public LinkedIn posts and news search results, which presents a surface for indirect prompt injection. \n
- Ingestion points: Data retrieved via
linkedin/companies/{slug}/postsandnews/search. \n - Boundary markers: No explicit delimiters are specified in the prompt templates to separate external data from system instructions. \n
- Capability inventory: The skill is restricted to read-only retrieval of public information and lacks the capability to write to the file system or execute shell commands. \n
- Sanitization: No specific sanitization or filtering logic is outlined for the external data content. Due to the limited capabilities of the skill, this is classified as a low-risk architectural characteristic.
Audit Metadata