linkedin

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose matches LinkedIn automation, and the npm install path looks coherent, but the core data flow is a third-party gateway that stores provider tokens and mediates all LinkedIn actions. Combined with public posting capabilities, this creates a meaningful security and trust risk disproportionate to a simple LinkedIn skill.

Confidence: 90%Severity: 68%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Flinkedin%2F@ca23d0a49278916fda50bedd290e16fd7cf0c0b1f8cce1c8de2c48385b2725c9
Security Audit — socket — linkedin