Zenity LinkedIn AI agent prompt injection claim - verification pass
Date: 2026-10-01 Verdict: UNVERIFIED (not refuted, not confirmed)
Claim under test
Mid-2025: Zenity (Zenity Labs, zenity.io) published research showing AI agents interacting with LinkedIn (AI headhunter / recruiting agent, agents reading LinkedIn messages) manipulated via prompt injection, including a demo where a LinkedIn AI agent was "phished". Possible demo name "Flower Sermon" (unconfirmed hint).
Findings
- Zenity's own blog index (https://zenity.io/blog), fetched in full: no LinkedIn-related post. No "Flower Sermon". No headhunter/recruiting agent post.
- Zenity Labs research index (https://zenity.io/labs), full list Jul 2024 through Sep 2026, including all of mid-2025: no LinkedIn-related research. No "Flower Sermon". Closest 2025 items are Copilot Studio, M365 Copilot EchoLeak, Salesforce, ChatGPT AgentFlayer, Amazon Q - none mention LinkedIn.
- No primary source found on the vendor's own site.
What was tried and blocked
- DuckDuckGo HTML search: bot captcha, no results.
- Bing search "Zenity Labs LinkedIn AI agent prompt injection headhunter" and ""Flower Sermon" zenity": query ignored, irrelevant results.
- Mojeek: HTTP 403.
- SearXNG (searx.be): browser bot check.
- https://zenity.io/labs.md: 404. https://zenity.io/post/hsc25: 404.
- Tool budget (10 calls) exhausted before news coverage (The Hacker News, SecurityWeek, BleepingComputer, Wired) could be checked, and before web.archive.org checks.
Status per key question
- Primary source (Zenity Labs post / researcher thread): NOT FOUND. Vendor's own indexes show no such research.
- Demo details (product, payload, action): UNVERIFIED.
- "Flower Sermon" as demo name: NOT CONFIRMED by any accessible source. Do not use it.
- LinkedIn public response: UNVERIFIED, not searched (budget exhausted).
Conclusion
Claim UNVERIFIED. Absence in Zenity's own complete research index is evidence against the claim, but news coverage could not be searched, so this is not a refutation.