Back to skill

Security audit

Linkedin Lead Gen

Security checks for vulnerabilities and agentic risk

Overview

This lead-generation skill is coherent, but it should be reviewed because it profiles LinkedIn prospects without privacy guardrails and generates unsafe HTML reports from untrusted data.

Review before installing. Use only for lawful, business-appropriate prospect research on public professional information, avoid sensitive personal data, respect LinkedIn and site terms, and do not open generated reports from untrusted or unreviewed input until the HTML escaping and URL validation issue is fixed.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The invocation text 'Use when asked to find potential clients or leads' is broad enough to trigger the skill for many generic sales or prospecting requests, including situations involving personal-profile collection and unsolicited outreach. Overbroad routing increases the chance the agent will apply this data-gathering workflow in contexts where the user did not explicitly intend LinkedIn scraping, profile compilation, or lead dossier creation.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs collection of personal and business profile information from LinkedIn and company websites into a compiled report, but gives no warning about privacy, platform terms, or responsible handling of personal data. In this context, the absence of a warning makes the workflow more dangerous because it normalizes bulk profiling of identifiable individuals for outreach without requiring minimization, lawful basis, or user acknowledgment.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The report generator interpolates untrusted prospect fields such as name, position, location, linkedin_url, needs, and pitch directly into HTML without escaping or URL validation. If any input contains HTML or JavaScript, opening the generated report in a browser could trigger stored XSS or HTML injection, which is especially relevant because this skill aggregates externally sourced LinkedIn/profile data that should be treated as untrusted.

Static analysis

No suspicious patterns detected.