linkedin-connect

Warn

Audited by Socket on Apr 8, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
scripts/batch-connect.js

No strong indicators of traditional malicious payload behavior (backdoor, system compromise, explicit data exfiltration, or obfuscation) are present in this single module. However, it is a high-privilege browser automation tool that can trigger connection requests on LinkedIn using CDP (Runtime.evaluate + UI clicking) and navigates to URLs derived from database content without validation. Additionally, it conditionally disables TLS certificate verification for database connections in an 'insforge'-identified configuration. Overall risk is moderate, driven more by abuse potential and automation power than by clear malware intent.

Confidence: 62%Severity: 60%
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is internally coherent for LinkedIn outreach, but it automates authenticated social actions using raw session cookies, database-driven lead targeting, and scheduled browser automation. There is no clear evidence of malware or credential exfiltration, yet the autonomy and credential model make it high-risk for account abuse and unintended outreach.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Apr 8, 2026, 08:23 AM
Package URL
pkg:socket/skills-sh/kevinbadi%2Fai-os-skills%2Flinkedin-connect%2F@e90af5d01b59ce66db87bf0da62568c53a4917d5
Security Audit — socket — linkedin-connect