linkedin-growth

Warn

Audited by Socket on Jul 21, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent for LinkedIn growth automation and uses a plausibly official npm-distributed CLI, but it enables autonomous scheduled outreach and routes tokens/actions through external tooling. The main concern is high-risk autonomy abuse, not confirmed malware.

Confidence: 89%Severity: 82%
AnomalyLOW
scripts/schedule.mjs

This module functions as a cross-platform persistence/task-scheduling installer that repeatedly executes a package-provided script (tick.mjs) via launchd/systemd/cron/schtasks. In the shown fragment there is no direct evidence of malware behaviors such as network exfiltration or credential theft, but the code has significant security sensitivity due to enabling recurring background execution and due to injection-prone string interpolation when embedding PATH and command arguments into scheduler configuration (especially the cron line with shell redirection). Full risk assessment requires reviewing the executed tick.mjs and any referenced helper modules (paths/config) for the actual behavior of the scheduled task.

Confidence: 46%Severity: 60%
Audit Metadata
Analyzed At
Jul 21, 2026, 03:44 PM
Package URL
pkg:socket/skills-sh/Linked-API%2Flinkedin-skills%2Flinkedin-growth%2F@e206aa5ea4eff8f2a0fdca02cc3bdc91fa70ee0f5d22b5360eb07d5b73a0aca3
Security Audit — socket — linkedin-growth