linkedin-cli

Warn

Audited by Socket on Mar 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's functionality matches its stated LinkedIn CLI purpose, but it authenticates by harvesting live browser session cookies and forwarding them to an unofficial third-party library that uses undocumented LinkedIn endpoints instead of official OAuth APIs. That creates significant credential-handling and data-flow risk even though there is no direct evidence of deliberate malware or hidden exfiltration.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Mar 22, 2026, 11:37 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Flinkedin-cli%2F@981b02c6dadfa9090662740e5bbe52e6177d0efb