linkedin-connect
Audited by Socket on Apr 8, 2026
2 alerts found:
AnomalySecurityNo strong indicators of traditional malicious payload behavior (backdoor, system compromise, explicit data exfiltration, or obfuscation) are present in this single module. However, it is a high-privilege browser automation tool that can trigger connection requests on LinkedIn using CDP (Runtime.evaluate + UI clicking) and navigates to URLs derived from database content without validation. Additionally, it conditionally disables TLS certificate verification for database connections in an 'insforge'-identified configuration. Overall risk is moderate, driven more by abuse potential and automation power than by clear malware intent.
SUSPICIOUS: The skill is internally coherent for LinkedIn outreach, but it automates authenticated social actions using raw session cookies, database-driven lead targeting, and scheduled browser automation. There is no clear evidence of malware or credential exfiltration, yet the autonomy and credential model make it high-risk for account abuse and unintended outreach.