linkedin

Warn

Audited by Socket on Mar 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The LinkedIn automation skill is broadly aligned with its stated purpose of manipulating LinkedIn content and profiles via browser automation. However, the install pathway relies on an external, unverifiable script (curl | bash from a non-official domain), which introduces supply-chain risk. The credential handling is dual-mode (manual login vs environment variables); while designed to be privacy-conscious, local credential storage raises risk on shared or compromised hosts. Data flows are largely confined to the user's session with LinkedIn, but session data and credentials stored locally create potential leakage points. Overall, the footprint is suspicious due to the unverifiable install source, with medium risk of credential exposure and autonomous action without per-step user confirmation. Treat as SUSPICIOUS with focus on securing install provenance and ensuring explicit per-action user consent and minimized credential exposure.

Confidence: 72%Severity: 62%
Audit Metadata
Analyzed At
Mar 11, 2026, 08:50 PM
Package URL
pkg:socket/skills-sh/manojbajaj95%2Fclaude-gtm-plugin%2Flinkedin%2F@f3be614245da7a8644a3ff9c7e31ae7cd53b57f9