linkedin-copywriter
Audited by Socket on Aug 30, 2026
3 alerts found:
SecurityAnomalyx2SUSPICIOUS. The core copywriting purpose is coherent, but the skill’s actual footprint depends on a third-party gtm-tools gateway for LinkedIn data access, session-backed reads, and outbound sends, plus a curl|bash installer for the required extension. That combination creates medium-high supply-chain and data-flow risk disproportionate to a drafting assistant, even though it does not show confirmed malware or stealth behavior.
No direct malware is evidenced in this fragment because it is documentation rather than executable code. However, the documented connect workflow that extracts a LinkedIn browser session cookie, combined with endpoints that send messages/invitations and access conversation history, represents a high-sensitivity capability set. This should be treated as a meaningful security and abuse-risk area and requires verification of server-side protections (secure session handling, strict authorization boundaries, auditing, rate limits, and anti-abuse controls).
SUSPICIOUS. The skill’s purpose and capabilities mostly align, and there is no install-chain abuse, but the real data flow is opaque and key features (employee directory and decision-maker search) do not clearly match documented public LinkedIn APIs from the provided evidence. That makes the backend provenance and compliance posture uncertain.