linkedin-automation
Pass
Audited by Gen Agent Trust Hub on Feb 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- EXTERNAL_DOWNLOADS (LOW): The skill instructs the user to add an external MCP server at
https://rube.app/mcp. This domain is not listed as a trusted source for agent skills. - DATA_EXFILTRATION (LOW): User LinkedIn profile and organizational data is transmitted to and processed by the
rube.appservice to perform its functions. - PROMPT_INJECTION (LOW): The skill exhibits an Indirect Prompt Injection surface because it ingests external data from LinkedIn and possesses write-access capabilities. \n
- Ingestion points: Profile data and company info retrieved via
LINKEDIN_GET_MY_INFOandLINKEDIN_GET_COMPANY_INFO. \n - Boundary markers: Absent. There are no instructions to delimit or ignore instructions within the retrieved content. \n
- Capability inventory: Tools for creating posts, comments, and deleting content (
LINKEDIN_CREATE_LINKED_IN_POST,LINKEDIN_CREATE_COMMENT_ON_POST,LINKEDIN_DELETE_LINKED_IN_POST). \n - Sanitization: Absent. The skill provides no mechanisms for validating or escaping content retrieved from external sources before use.
Audit Metadata