keyapi-linkedin-user-analytics

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent for LinkedIn intelligence gathering and does not show classic malware patterns or deceptive installers, but it routes all activity and the API token through a third-party hosted MCP gateway instead of official LinkedIn APIs, and it stores potentially sensitive profile/contact data locally. Main risk is intermediary trust and privacy exposure, not confirmed malicious intent.

Confidence: 88%Severity: 64%
Audit Metadata
Analyzed At
Mar 24, 2026, 12:11 PM
Package URL
pkg:socket/skills-sh/EchoSell%2Fkeyapi-skills%2Fkeyapi-linkedin-user-analytics%2F@2ffa95a611da5d4019fdb550e574ef6895be2d0a