linkedin-project-post

Fail

Audited by Socket on Feb 17, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Natural language instruction to download and install from URL detected All findings: [CRITICAL] command_injection: Natural language instruction to download and install from URL detected (CI009) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] Benign: The code fragment is coherently aligned with its stated purpose of generating and optionally auto-publishing LinkedIn posts for coding projects, including optional screenshot capture and MCP-based posting. Data flows and permissions are proportional to the stated functionality; no unexpected credential harvesting or data leakage patterns are evident in the fragment. The MCP configuration guidance is user-supplied and not embedded secrets in the code. LLM verification: This skill's stated purpose (generate LinkedIn posts and capture screenshots) matches its capabilities, but its recommended execution path exposes sensitive data and credentials to third‑party services and encourages running remote tooling. There is no direct evidence of obfuscated or malicious code in the SKILL.md itself, but the auto-posting and external screenshot flows are high-risk if the MCP servers or screenshot APIs are untrusted. Recommend marking this skill as SUSPICIOUS for supply-cha

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 17, 2026, 08:36 PM
Package URL
pkg:socket/skills-sh/alfredang%2Fskills%2Flinkedin-project-post%2F@5273a7ecfbc33a7452602ae7bd95af2b2cac5119