Back to skill

Security audit

Linkedin Post

Security checks for vulnerabilities and agentic risk

Overview

This is a local LinkedIn content logging tool with disclosed persistence, but users should treat saved drafts and exports as plaintext local data.

Install only if you are comfortable with LinkedIn drafts, schedules, strategy notes, and command history being saved as plaintext under ~/.local/share/linkedin-post. Avoid confidential client or employer content unless you have checked local file permissions, and be careful opening CSV exports in spreadsheet software. The tool appears to be a local tracker more than an AI generator, and it lacks built-in purge, retention, or private-mode controls.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:6
Finding

Potentially Sensitive Content Is Stored Without Restrictive Permissions

Content
View full analysis
/dev/null || echo " No entries yet. Use: linkedin-post draft " else local input="$*" local ts=$(date '+%Y-%m-%d %H:%M') echo "$ts|$input" >> "$DATA_DIR/draft.log" local total=$(wc -l < "$DATA_DIR/draft.log") echo " [Linkedin Post] draft: $input" echo " Saved. Total draft entries: $total" _log "draft" "$input" fi ;; ``` ### Technical Analysis The script creates its data directory and log files without setting a restrictive `umask` or explicitly enforcing permissions. Consequently, effective permissions depend on the environment from which the command is invoked. With a common `umask` of `022`, the directory can be created with mode `0755`, while newly created log and export files can receive mode `0644`. On a multi-user system, these modes can allow other local accounts to enumerate the data directory and read its contents. The stored information can include unpublished LinkedIn drafts, schedules, rewrite notes, content strategies, translations, and complete activity history. Export files are created in the same directory and inherit the same permissions issue. ### Attack Path 1. A victim runs a content command such as `linkedin-post draft "confidential campaign details"`. 2. The script creates `~/.local/share/linkedin-post` and its log files using permissions derived from the victim's current `umask`. 3. If those permissions grant access to other local users, another account locates the predictable directory. 4. ...[truncated 700 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:76
Finding

CSV Export Allows Spreadsheet Formula Injection

Content
View full analysis
"$out" for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do echo "$name,$ts,$val" >> "$out" done < "$f" done ;; ``` ### Technical Analysis The `value` field originates from user-controlled command arguments and is inserted directly into a CSV row. The implementation performs neither standards-compliant CSV quoting nor spreadsheet formula neutralization. Values containing commas, quotation marks, carriage returns, or line feeds can alter the CSV structure. More importantly, spreadsheet applications may interpret a cell beginning with characters such as `=`, `+`, `-`, or `@` as a formula rather than plain text. Therefore, attacker-controlled content stored in any log can become an active spreadsheet expression when the victim exports the data and opens it in compatible spreadsheet software. The exact behavior and security impact depend on the spreadsheet application and its security configuration. ### Attack Path 1. Attacker-controlled or untrusted content is passed to a logging command, for example as a draft or editing note beginning with `=`, `+`, `-`, or `@`. 2. The script saves that content without validation. 3. The victim runs `linkedin-post export csv`. 4. The export routine writes the content directly into `export.csv` without quoting or neutralization. 5. The victim opens the CSV file in spreadsheet software. 6. The spreadsheet interprets the crafted cell as a formula. 7. Depending on the software and enabled features, the formula may initiate external requests, expose spreadsheet data, mislead the user, or invoke other unsafe functionality. ### Impact Assessment The script itself does not execu ...[truncated 455 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/script.sh:57
Finding

User-Controlled Content Is Exported Without JSON Escaping

Content
View full analysis
"$out" local first=1 for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do [ $first -eq 1 ] && first=0 || echo "," >> "$out" printf ' {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out" done < "$f" done echo "" >> "$out" echo "]" >> "$out" ;; ``` ### Technical Analysis The export routine constructs JSON by interpolating strings directly into a JSON object. It does not escape quotation marks, backslashes, control characters, or other characters with special meaning in JSON. Because `val` originates from user-supplied content, a crafted value can terminate the intended string, inject additional JSON syntax, or make the output invalid. Ordinary content containing quotation marks or backslashes can also corrupt the export without malicious intent. This is a data-integrity vulnerability rather than direct code execution within the Bash process. Additional security consequences can arise if a downstream application consumes the generated export while assuming that its structure is trustworthy. ### Attack Path 1. A crafted value containing JSON metacharacters is supplied to a content command. 2. The script stores the value in the corresponding log file. 3. The victim runs `linkedin-post export json`. 4. The export routine inserts the value into a JSON string without escaping. 5. The resulting `export.json` is malformed or contains attacker-influenced structure. 6. A downstream parser rejects the export, or an application that processes the altered structure acts on data outside the intended `value` field. ### Impact Assessment The immediate impact is corruption of exported data and loss of ...[truncated 394 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill presents itself as a content-generation assistant, but the documented behavior includes broad persistent logging, history tracking, search, export, and operational reporting that materially expand its data-handling scope. This mismatch can mislead users into providing sensitive drafts or business content without realizing it will be retained and exportable, increasing confidentiality and privacy risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description does not warn users that all entered content and command activity are written to persistent local log files. Users may paste confidential marketing plans, client details, or unpublished announcements assuming ephemeral processing, which creates avoidable data exposure on shared or compromised systems.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The examples and documented design confirm that user content persists across sessions in local logs and history files. Session persistence is not inherently malicious, but for a writing tool it can retain sensitive unpublished content, campaign strategy, or personal data longer than users expect, especially on multi-user endpoints.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
# Add hashtag ideas
linkedin-post hashtags "#SaaS #StartupLife #ProductLaunch #IndieHacker #BuildInPublic"

# Write a CTA
linkedin-post cta "Drop a 🔥 if you've shipped something this month. I'll check out your project."

# Schedule the post

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script silently creates a persistent data directory and logs user content/activity locally, but the skill description does not disclose retention or storage behavior. For a writing assistant, users may paste drafts, personal branding text, or sensitive business content, so undisclosed persistence increases the risk of unintended local exposure and secondary disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script persistently stores user-provided content and activity history without any up-front warning, consent prompt, or privacy notice. In the context of a LinkedIn writing assistant, users are likely to input unpublished posts, employer details, strategy notes, or personal profile information, making silent retention a meaningful privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

User content is stored, then made searchable and exportable through convenience commands, which increases the likelihood of broad disclosure of prior inputs. In this skill context, the stored data may include sensitive drafts, confidential campaign text, or personal profile information, and plain-text logs/exports make accidental exposure easier if the local account or files are accessed by others.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a writer tool for hooks, hashtags, carousel planning, comments, and profile optimization. In contrast, the implemented commands shown in help and dispatch merely accept user input, append it to local log files, and later display/export/search that stored text; there is no generation, planning, optimization, or LinkedIn-specific transformation logic in the script.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Functions for stats, export, and search create a general-purpose datastore over user content rather than directly supporting post generation, hooks, hashtags, carousel planning, comments, or profile optimization. While not inherently malicious, these capabilities are ancillary and materially broader than the manifest's stated writing-assistant scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.