linkedin-engineer

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s stated purpose is benign documentation/persona guidance, but its install path is not proportionate: it imports mutable third-party raw GitHub content from a personal repo into persistent Claude memory rather than using an official skill mechanism. No credential theft or exfiltration is evident, so this is not malware, but the transitive trust and persistence make it a medium supply-chain risk.

Confidence: 91%Severity: 62%
Audit Metadata
Analyzed At
Mar 31, 2026, 06:25 AM
Package URL
pkg:socket/skills-sh/theneoai%2Fawesome-skills%2Flinkedin-engineer%2F@b2d6f0c30718aaf694731a020b525fa44a340f68