linkedin-project-post

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. Drafting post text fits the stated purpose, but the skill expands into automatic public posting and third-party MCP setup that receives LinkedIn credentials. The main risk is credential forwarding plus autonomous social-media actions through unofficial integrations, not confirmed malware.

Confidence: 89%Severity: 79%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:14 PM
Package URL
pkg:socket/skills-sh/alfredang%2Fskills%2Flinkedin-project-post%2F@5273a7ecfbc33a7452602ae7bd95af2b2cac5119