linkedin-account-research

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it retrieves and processes content from public LinkedIn sources such as posts, job descriptions, and user profiles.\n
  • Ingestion points: Data is ingested from external LinkedIn company pages, posts, and member profiles via the unifapi skill endpoints.\n
  • Boundary markers: The instructions do not define clear delimiters or specific guidance for the agent to ignore or isolate potential instructions embedded within the fetched LinkedIn data.\n
  • Capability inventory: The skill's functionality is limited to generating text-based account briefs and discovery questions; no capabilities for arbitrary command execution or unauthorized file system access were identified.\n
  • Sanitization: No explicit sanitization or filtering of the retrieved external data is performed before it is incorporated into the prompt context.\n- [EXTERNAL_DOWNLOADS]: The skill documentation references external resources for installation and data retrieval.\n
  • The skill connects to a vendor-provided MCP server at https://mcp.unifapi.com for LinkedIn data access.\n
  • Installation instructions involve using npx to add skills from the unifapi-agent repository. These resources are associated with the skill's official author and infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 10:29 AM
Security Audit — agent-trust-hub — linkedin-account-research