LinkedIn Automation

Warn

Audited by Socket on Jun 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The stated purpose matches LinkedIn marketing automation, but the implementation footprint is not fully proportionate because it appears to rely on an unrelated third-party MCP relay instead of a transparent direct LinkedIn API integration. The biggest risk is data-flow opacity: account access, messages, posts, analytics, and lead data may pass through `social-mcp`, with no clear official OAuth flow or credential custody explanation. Not confirmed malware, but the remote intermediary and autonomous posting/messaging capabilities make this a medium-high risk skill.

Confidence: 82%Severity: 76%
Audit Metadata
Analyzed At
Jun 3, 2026, 02:53 PM
Package URL
pkg:socket/skills-sh/claude-office-skills%2Fskills-hub%2Flinkedin-automation%2F@8418d9e07c8763a66071e7c996e2371f9d88d71b
Security Audit — socket — LinkedIn Automation