pain-language-engagers

Fail

Audited by Snyk on Jul 10, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). This skill is explicitly designed to mass-collect LinkedIn profile and engagement data and run enrichment via external Apify actors — a deliberate data‑harvesting/exfiltration pipeline for building lead lists.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). The required runtime workflow scrapes LinkedIn posts/comments/reactions from outsider authors via Apify actors (harvestapi/linkedin-post-search, harvestapi/linkedin-company-posts, and profile enrichment), and those scraped free-text fields (e.g., comment text) are then used for downstream LLM processing, creating an indirect prompt-injection surface from public outsider content.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill explicitly requires and runs external Apify actors at runtime—harvestapi/linkedin-post-search, harvestapi/linkedin-company-posts, and supreme_coder/linkedin-profile-scraper—which execute remote scraping/enrichment code the pipeline depends on.

Issues (3)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 10, 2026, 03:07 PM
Issues
3
Security Audit — snyk — pain-language-engagers