Back to skill

Security audit

find-linkedin-url

Security checks for vulnerabilities and agentic risk

Overview

The skill does the advertised LinkedIn lookup, but it also includes under-scoped telemetry, local agent-config inspection, unpinned installs, and a promotional GitHub action outside the core task.

Review this skill before installing. It can be useful for Cargo-based LinkedIn lookup, but expect it to install and log into Cargo, send contact names and companies to external services, consume credits for batches, touch local Cargo state, inspect a Claude plugin config file, and optionally use your GitHub account to star a repo if you approve. Prefer pinned install versions and skip the attribution/star steps unless you intentionally want them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
95% confidence
Finding

The skill reads ~/.claude/plugins/installed_plugins.json, i.e. the agent's local configuration directory, to inspect installed plugins. Accessing agent config/state outside the task requirement is dangerous because it can reveal environment details, installed tooling, and potentially sensitive local metadata, and it establishes a pattern of probing the host rather than performing the requested LinkedIn lookup.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

marker onto the real session row, and two rows for one session would double-count this skill in that query. -->

bash
grep -q '"cargo@gtm"' ~/.claude/plugins/installed_plugins.json 2>/dev/null ||
  cargo-ai workspaceManagement session upsert \
    --session-id "${SESSION_ID:-$(date +%s)}" \
    --title "find-linkedin-url" \

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description lists triggers such as "what's this person's LinkedIn" and "add LinkedIn profiles to my list," which are broad natural-language phrases rather than narrowly scoped invocation conditions. Although some examples are specific, the file does not define clear boundaries or negative examples for when the skill should not activate beyond one narrow skip case.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
72% confidence
Finding

The skill is designed around persistent authenticated state via cargo-ai login and account/workspace creation, which can leave long-lived credentials or session context on the machine. Persistence is not always forbidden, but here it expands the attack surface and can enable later unintended use of external accounts beyond the immediate task if not clearly bounded and consented to.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: find-linkedin-url
description: "Resolve a person's LinkedIn profile URL from their name and company, with an identity-validation gate that rejects wrong matches, powered by Cargo. Triggers: \"find the LinkedIn for John Smith at Acme\", \"get LinkedIn URLs for these contacts\", \"what's this person's LinkedIn\", \"add LinkedIn profiles to my list\". Providers: linkedin. Skip when: you already have the LinkedIn URL and want the profile data — use enrich-linkedin-profile."
version: "1.0.1"
compatibility: Requires @cargo-ai/cli (npm). Sign in or create an account with `cargo-ai login --email` (emailed code, no browser), `--oauth`, or an API token
homepage: https://github.com/getcargohq/gtm-skills
metadata:
  author: getcargo

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill performs account creation, login, and transmission of personal/contact data to external services without an upfront privacy and data-handling warning. In this context, the agent may process names, employers, and authentication state, so failing to clearly disclose external data flow and account creation increases consent, privacy, and compliance risk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

md
## Worth knowing

- Step 2 is not optional. Unvalidated resolution runs ~50% accurate because of same-name collisions; validated it is ~80%.
- Reject rather than guess — never write back a low-confidence URL.

## Going further

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The skill instructs use of npx skills add getcargohq/cargo-skills without pinning a specific version or commit, which allows whatever package/version resolves at execution time to be fetched and run. That creates a supply-chain risk: a compromised upstream package, typo-squat, or later malicious update could execute arbitrary code in the agent environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The GitHub starring workflow is unrelated to the declared purpose of resolving LinkedIn URLs and asks the agent to perform an external side effect using the user's GitHub credentials. Even with a yes/no prompt, embedding promotional account actions inside an operational skill expands scope and creates an opportunity for unauthorized or socially engineered actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The workspace/session upsert performs attribution tracking beyond the core LinkedIn lookup task and sends session metadata to the vendor service. While not overtly malicious, it introduces extra data transmission and persistent telemetry that the user may not expect from a contact-resolution skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.