linkedin-api

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes instructions to use curl for interacting with the LinkedIn API for OAuth token exchange, publishing content, and fetching analytics. These are standard API operations for the skill's purpose.
  • [COMMAND_EXECUTION]: A local bash script scripts/verify.sh is provided to perform static analysis of the workspace. It checks for the presence of mandatory metadata in generated wiki files and scans for hardcoded LinkedIn credentials (client secrets and access tokens) using regex to prevent accidental commits of sensitive data.
  • [CREDENTIALS_SAFE]: The skill explicitly warns against committing secrets to source control, recommending the use of environment variables (e.g., process.env.LINKEDIN_CLIENT_SECRET). The scripts/verify.sh script actively enforces this policy by failing if it detects potential secret literals.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:56 AM
Security Audit — agent-trust-hub — linkedin-api