linkedin-api
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes instructions to use
curlfor interacting with the LinkedIn API for OAuth token exchange, publishing content, and fetching analytics. These are standard API operations for the skill's purpose. - [COMMAND_EXECUTION]: A local bash script
scripts/verify.shis provided to perform static analysis of the workspace. It checks for the presence of mandatory metadata in generated wiki files and scans for hardcoded LinkedIn credentials (client secrets and access tokens) using regex to prevent accidental commits of sensitive data. - [CREDENTIALS_SAFE]: The skill explicitly warns against committing secrets to source control, recommending the use of environment variables (e.g.,
process.env.LINKEDIN_CLIENT_SECRET). Thescripts/verify.shscript actively enforces this policy by failing if it detects potential secret literals.
Audit Metadata