linkedin-copywriter

Warn

Audited by Socket on Aug 30, 2026

3 alerts found:

SecurityAnomalyx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core copywriting purpose is coherent, but the skill’s actual footprint depends on a third-party gtm-tools gateway for LinkedIn data access, session-backed reads, and outbound sends, plus a curl|bash installer for the required extension. That combination creates medium-high supply-chain and data-flow risk disproportionate to a drafting assistant, even though it does not show confirmed malware or stealth behavior.

Confidence: 84%Severity: 76%
AnomalyLOW
references/tools-reference.md

No direct malware is evidenced in this fragment because it is documentation rather than executable code. However, the documented connect workflow that extracts a LinkedIn browser session cookie, combined with endpoints that send messages/invitations and access conversation history, represents a high-sensitivity capability set. This should be treated as a meaningful security and abuse-risk area and requires verification of server-side protections (secure session handling, strict authorization boundaries, auditing, rate limits, and anti-abuse controls).

Confidence: 42%Severity: 62%
AnomalyLOW
companies/SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align, and there is no install-chain abuse, but the real data flow is opaque and key features (employee directory and decision-maker search) do not clearly match documented public LinkedIn APIs from the provided evidence. That makes the backend provenance and compliance posture uncertain.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Aug 30, 2026, 05:07 PM
Package URL
pkg:socket/skills-sh/arnaudjnn%2Fgtm-skills%2Flinkedin-copywriter%2F@a460aa230213b595d4b33581b6f38714729e89a0ee778c854741c0b38523fcf0
Security Audit — socket — linkedin-copywriter