linkedin-message-writer

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and core behavior are mostly aligned: it researches LinkedIn leads, writes outreach copy, and exports CSVs. The main risk is trust delegation to third-party HarvestAPI actors on Apify using the user's APIFY_API_TOKEN; this is broader than a simple first-party API integration, though not clear malware or credential theft. Data flows stay on official Apify endpoints, requested access is limited to one relevant token, and there is no remote-code install path. Overall this is a coherent but moderately risky outreach automation skill due to third-party actor reliance and scaled personal-data processing.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
May 17, 2026, 01:39 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Flinkedin-message-writer%2F@f6870d45a14e386e98e095c08a3c95f9527d4357
Security Audit — socket — linkedin-message-writer