linkedin

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The LinkedIn skill presents a coherent purpose as a comprehensive automation CLI; however, its footprint introduces notable security and compliance concerns: reliance on a third-party cloud-browser service for LinkedIn actions, handling of authentication tokens via user-provided tokens, and potential data exfiltration through JSON outputs and external endpoints. The absence of explicit secure-by-design measures (token redaction in logs, explicit TLS/pinning details, auditable source of the Linked API client, and adherence to LinkedIn's terms) elevates risk. Overall, the capability-set is broadly aligned with the stated purpose, but the trust and data-flow patterns warrant being classified as SUSPICIOUS with a leaning toward MEDIUM risk until source integrity, data handling, and compliance controls are clarified and verified.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 08:16 PM
Package URL
pkg:socket/skills-sh/linked-api%2Flinkedin-skills%2Flinkedin%2F@6a2dcb7aae4346e21399c8a72e4ed64cb0678015