linkedin-dm

Fail

Audited by Socket on Feb 14, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The code/spec implements a legitimate automation for personalized LinkedIn outreach but depends on high‑privilege components (browser session access and Google Sheets access) and unspecified auxiliary tools ('gog' CLI, browser extension/managed profile). There is no direct evidence of embedded malware or obfuscated malicious code in this document, however the supply‑chain and operational risks are significant: untrusted extensions or an unknown CLI could capture session tokens, message contents, and contact lists. Before use: verify provenance and source code of 'gog' and any browser extension/OpenClaw components, restrict OAuth scopes to the minimum required, run automation locally where possible, audit any third‑party binaries, and limit campaign volume to avoid account suspension.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 14, 2026, 02:13 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Flinkedin-dm%2F@fc0009f83ce50bc5fd2777dbfa00f137f7f075cc