connections-optimizer
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [SAFE]: No malicious patterns, persistence mechanisms, or credential exposures were detected. The skill prioritizes user oversight through a 'review-first' policy for all network modifications and outbound messaging.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted content from social media profiles to inform decision-making and message drafting.
- Ingestion points: Network inventory and activity data retrieved from X (via API) and LinkedIn (via browser control).
- Boundary markers: Absent; the skill does not explicitly define delimiters to isolate external profile data from its own instructional logic.
- Capability inventory: Generates ranked action plans, drafts messages across multiple channels, and modifies social graphs.
- Sanitization: No evidence of data sanitization or input validation for retrieved profile metadata before it is processed by the agent.
- [COMMAND_EXECUTION]: Employs desktop automation to interface with Apple Mail/Mail.app for creating email drafts.
- This capability is limited to draft creation only and explicitly prohibits automatic sending, adhering to a manual-review workflow.
Audit Metadata