linkedin

Warn

Audited by Socket on Aug 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent and uses a verifiable npm-distributed CLI from the same vendor, so it does not look like disguised malware. However, its core model routes credentials, LinkedIn activity, and extracted data through a non-LinkedIn third-party cloud browser service and enables autonomous outbound actions with public or account-level consequences. That combination makes it higher risk than a read-only integration, even though the documentation warns to obtain user approval before writes.

Confidence: 90%Severity: 71%
Audit Metadata
Analyzed At
Aug 8, 2026, 03:37 PM
Package URL
pkg:socket/skills-sh/yangsonhung%2Fawesome-agent-skills%2Flinkedin%2F@9aa24b8867a2b19baaad8f2c7dfe2c524941c7c2a9ce7fee6a1f4bc520cf380c
Security Audit — socket — linkedin