linkedin-marketing

Warn

Audited by Socket on Sep 6, 2026

1 alert found:

Anomaly
AnomalyLOW
.codex-marketplace/linkedin-skills/skills/linkedin-engager-analytics/SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align, and it has good safeguards against prompt injection, but its data flow depends on Apify-hosted scraping rather than an official LinkedIn API, and the exact upstream actor is not identified. That makes APIFY_TOKEN and engagement data exposure to third-party actor code the main concern, yielding medium security risk rather than confirmed malware.

Confidence: 83%Severity: 55%
Audit Metadata
Analyzed At
Sep 6, 2026, 08:37 PM
Package URL
pkg:socket/skills-sh/sergebulaev%2Flinkedin-skills%2Flinkedin-marketing%2F@e99034faca51bb5827370f873ecd3f005f1c6bc7
Security Audit — socket — linkedin-marketing