LinkedIn Lead Gen Outreach

Security checks across malware telemetry and agentic risk

Overview

This is a review-first LinkedIn lead workflow with local CSV/Sheets helpers and no evidence of hidden automation or data exfiltration.

Install only if you have a lawful, policy-compliant reason to process prospect data. Keep generated CSV or Sheets files in controlled locations, minimize fields to what you need, set retention limits, and manually review messages before outreach.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill explicitly collects, scores, drafts outreach for, and exports identifiable prospect data such as full names, LinkedIn URLs, titles, companies, and locations, but it lacks clear privacy, retention, consent, and handling safeguards. In a lead-generation context, this increases the risk of unnecessary PII collection, over-sharing in exports, and noncompliant downstream use of personal data.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal