Back to skill

Security audit

Agenticflow Skill

Security checks across malware telemetry and agentic risk

Overview

This LinkedIn automation skill is disclosed, but it would let an agent act on private messages, posts, invitations, and possibly browser sessions without enough opt-in or scope controls.

Review this carefully before installing. It should require separate opt-in for private-message automation, previews or approval before replies are sent, clear limits on invitation handling and posting, and a preference for official LinkedIn API access with least-privilege OAuth scopes over browser scraping.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The workflow explicitly states that it will scan unread LinkedIn messages and apply predefined replies, but the skill description does not warn the user that this automates private communications on their behalf. That omission is risky because users may unknowingly enable behavior that can misrepresent them, send unintended responses, or violate platform or organizational communication policies.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The prerequisites mention 'scraping via browser-automation' as an alternative to the official LinkedIn API, but the skill does not warn that this can violate LinkedIn terms, trigger account restrictions, and involve sensitive session handling. Presenting scraping as a normal option without caution increases the likelihood of unsafe or non-compliant automation being deployed.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.