Back to skill

Security audit

Linkedin Lead Generation

Security checks for vulnerabilities and agentic risk

Overview

This LinkedIn lead-generation skill is mostly purpose-aligned, but its report generator can place untrusted profile and website data directly into HTML reports without escaping it.

Review before installing. Use it only for lawful, user-directed B2B prospecting, avoid collecting unnecessary personal details, and treat generated reports as sensitive. The report generator should escape all displayed fields and restrict profile links to safe URL schemes before use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_report.py:36
Finding

Unescaped Prospect Data Allows HTML and Script Injection in Generated Reports

Content
View full analysis
{p['name']}
{p['position']}
Location: {p.get('location', 'N/A')} | LinkedIn Profile

Gap Analysis:

    """ for need in p.get('needs', []): html += f"
  • {need}
  • " html += f"""
Pitch Idea: {p.get('pitch', 'N/A')} ``` ### Technical Analysis `generate_html()` parses JSON and directly interpolates prospect-controlled fields into an HTML document. The fields `name`, `position`, `location`, `linkedin_url`, each item in `needs`, and `pitch` are not HTML-escaped. An attacker-controlled value containing HTML, such as an image with an event handler or a closing tag followed by a script element, can break out of the intended document structure. The `linkedin_url` field is also inserted into an `href` attribute without validating its scheme, allowing dangerous values such as `javascript:` URLs. The Skill’s workflow obtains information from LinkedIn profiles and external company websites. If content derived from those sources is copied into the prospect JSON, the report generator treats that external data as trusted markup. Exploitability depends on whether the resulting HTML is opened in a browser or processed by a PDF renderer that permits JavaScript, external resource loading, or local-resource access. ### Attack Path 1. An attacker places craf ...[truncated 1446 chars]
Remediation
View remediation
javascript:alert(document.domain) ``` The tests should confirm that markup is rendered as text and that unsupported URL schemes are rejected. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is broad enough to trigger on generic lead-finding or prospecting requests, which can cause the agent to invoke a workflow that performs targeted scraping/research of individuals without clear user intent boundaries. In this context, the skill explicitly directs LinkedIn profile review, company-site analysis, and report generation, so accidental or overbroad activation increases privacy, compliance, and misuse risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill instructs the agent to create an HTML-based PDF report but does not warn that it will generate a persistent output artifact. This can surprise users, create unintended storage of prospect data, and increase the chance that sensitive business or personal information gathered during research is retained or shared beyond the immediate session.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The generated document sets lang="en", which forces an English locale in output. Under the policy rules, a fixed language/locale choice without user opt-in can be a natural-language policy violation when no alternative or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.