linkedin-scheduling

Warn

Audited by Socket on Jul 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The advisory content itself is benign and on-topic, but the skill expands into installing an unpinned external MCP package and forwarding an API key to it. Because the provided evidence does not verify `@coldiq/mcp` as a clearly traceable official package with a public release trail, the install/credential trust is disproportionate to a LinkedIn scheduling skill.

Confidence: 82%Severity: 80%
Audit Metadata
Analyzed At
Jul 22, 2026, 06:39 PM
Package URL
pkg:socket/skills-sh/Cold-IQ%2FColdIQ-s-GTM-Skills%2Flinkedin-scheduling%2F@401ba2e8ed3dc14be8b7b532d89219fbc61997898b65cdac8a5466a9e2569472
Security Audit — socket — linkedin-scheduling