linkedin-cn

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Vulnerability Surface. The skill is designed to ingest and process untrusted data from LinkedIn (such as profiles, search results, and messages) and has the capability to perform write actions based on that data.
  • Ingestion points: The linkedin command-line tool fetches external content including profiles, company pages, and search results (SKILL.md).
  • Boundary markers: The instructions lack explicit delimiters or markers to isolate retrieved untrusted data from the agent's internal instruction set.
  • Capability inventory: The skill possesses significant interaction capabilities, including sending private messages, connection requests, posting updates, and commenting (SKILL.md).
  • Sanitization: No specific sanitization or filtering logic is described for handling external content before it enters the agent context.
  • [DATA_EXFILTRATION]: Sensitive Data Handling. The skill's primary function requires the management of sensitive LinkedIn session cookies, access tokens, and API credentials.
  • Evidence: The skill documentation explicitly references the use of "LinkedIn credentials, session cookies, or access tokens" and "Linked API credentials" (SKILL.md).
  • [COMMAND_EXECUTION]: Local Tool Usage. The skill relies on a linkedin command-line utility to interact with the Linked API cloud browser infrastructure.
  • Evidence: Mentions execution of the linkedin CLI tool for all core functions (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 03:37 PM
Security Audit — agent-trust-hub — linkedin-cn