LinkedIn Post Engine

Security checks across malware telemetry and agentic risk

Overview

This skill is a LinkedIn writing assistant made only of Markdown guidance, with no code, account access, credential use, persistence, or publishing authority.

Reasonable to install as a drafting aid. Review generated posts for factual accuracy, authenticity, and brand fit before publishing, especially because the skill is designed to improve engagement.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description is broad enough to trigger on many ordinary writing-related requests, which can cause the agent to invoke this skill outside clearly intended LinkedIn-specific use cases. Overly broad invocation expands the skill’s reach and may override more appropriate skills or expose users to unintended prompt steering, even though the content itself is not overtly malicious.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal