Back to skill

Security audit

Linkedin Profile Optimizer

Security checks across malware telemetry and agentic risk

Overview

This is a text-only LinkedIn profile optimization skill with a minor routing ambiguity but no evidence of hidden execution, credential use, or unsafe actions.

Safe to install for LinkedIn profile rewriting and audit work. Be aware that generic requests like "fix my headline" or "optimize bio" might route here even outside LinkedIn, so confirm the intended platform before sharing personal profile content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrases in the metadata are broad enough to match generic profile-editing requests such as 'fix my headline' or 'optimize bio' without a strong LinkedIn-specific constraint. This can cause the skill to activate in contexts the user did not intend, leading to inappropriate handling of unrelated profile content and increased prompt-routing risk.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The 'When to use' guidance includes ambiguous phrases like 'fix my headline' and 'optimize bio' that are common across many platforms, which makes activation criteria insufficiently constrained. In an agentic environment, this ambiguity can misroute user requests to this skill, causing incorrect transformations of content or unintended collection of profile data for the wrong platform.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.