linkedin-scheduling
Warn
Audited by Socket on Jul 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The advisory content itself is benign and on-topic, but the skill expands into installing an unpinned external MCP package and forwarding an API key to it. Because the provided evidence does not verify `@coldiq/mcp` as a clearly traceable official package with a public release trail, the install/credential trust is disproportionate to a LinkedIn scheduling skill.
Confidence: 82%Severity: 80%
Audit Metadata