LinkedIn Automation
Warn
Audited by Socket on Jun 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The stated purpose matches LinkedIn marketing automation, but the implementation footprint is not fully proportionate because it appears to rely on an unrelated third-party MCP relay instead of a transparent direct LinkedIn API integration. The biggest risk is data-flow opacity: account access, messages, posts, analytics, and lead data may pass through `social-mcp`, with no clear official OAuth flow or credential custody explanation. Not confirmed malware, but the remote intermediary and autonomous posting/messaging capabilities make this a medium-high risk skill.
Confidence: 82%Severity: 76%
Audit Metadata