T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Unpinned Third-Party Dependency Receives Privileged System Access
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This LinkedIn inbox skill is mostly purpose-aligned, but it can read private messages and send LinkedIn messages through a live browser session without strong built-in approval, recipient verification, or retention controls.
Review before installing. Use only with a dedicated browser profile or account, restrict the Discord channel, avoid retaining screenshots unless necessary, and do not rely on the included send script unless you add an explicit approval token, stable recipient verification, rate limiting, and fail-closed UI checks.
SKILL.md:12Unpinned Third-Party Dependency Receives Privileged System Access
scripts/scan_inbox.sh:7Private LinkedIn Captures Are Written to Predictable Temporary Paths
scripts/send_message.sh:26Message-Sending Script Does Not Enforce Approval or Verify the Selected Recipient
The declared description presents a LinkedIn inbox management assistant focused on scanning messages, drafting replies, approval workflows, and summaries. The supplied code does not implement those behaviors. Instead, it performs a narrow browser automation task: opening Chrome, navigating to a LinkedIn messaging URL for a specified person, and taking a screenshot. Screenshot capture of conversation content is a substantive capability not mentioned in the description, and the primary purpose is materially different from inbox management and response drafting.
The declared description presents a broader LinkedIn inbox management skill that scans messages, drafts replies, follows user style, and supports approval workflows and summaries. The supplied code only automates Chrome to open LinkedIn messaging and captures the inbox state as an image/JSON artifact. While this partially aligns with the 'scheduled scanning/monitoring' aspect, the primary implemented behavior is UI navigation and screenshot capture, and major declared capabilities like auto-drafting responses, approval flows, off-hours management, and summaries are absent. Additionally, the code uses undeclared browser automation and local file capture/storage of inbox contents, which are meaningful capabilities not reflected in the description.
The declared description emphasizes inbox management, scheduled monitoring, drafting replies, and approval-based workflows. The supplied code instead implements a narrow automation for directly sending a message to a named LinkedIn conversation through browser UI control. While LinkedIn messaging is related to the stated domain, the actual behavior omits the core declared features and includes immediate message sending without any visible approval step, which is materially different from the described approval-oriented drafting workflow.
The screenshot operation captures the full LinkedIn conversation context from the live browser, which can expose message contents, participant identities, and other visible account data beyond the minimum needed for the task. In an inbox-management skill, this materially increases the chance of leaking sensitive communications or unrelated on-screen information through image files or downstream processing.
peekaboo press return --app "Google Chrome"
sleep 3
# Capture the conversation
OUTPUT_PATH="/tmp/linkedin-conversation-$(date +%s).png"
peekaboo see \
--app "Google Chrome" \
The skill captures screenshots of LinkedIn inbox content and posts message previews and draft replies to an external notification channel, but the description does not clearly warn that private message contents and profile details may be collected, stored, and shared. This creates a meaningful privacy and data-handling risk, especially if the Discord channel is broader than intended or screenshots persist on disk.
The activation phrase 'Start LinkedIn inbox monitoring' and similar natural-language triggers are broad enough that an agent could begin privacy-sensitive inbox scanning from an ambiguous or casually phrased request. Because this skill reads private messages and may draft or later send replies, unintended invocation could expose sensitive communications or trigger unwanted monitoring.
The instruction to 'Log everything' in a daily memory file encourages retention of potentially sensitive LinkedIn message contents, sender identities, drafts, and user approval actions in natural-language memory. Such logs can become a secondary leakage source, be over-shared to other tools or agents, or persist longer than necessary without access controls.
The script captures a screenshot of a LinkedIn conversation and writes it to /tmp, which may contain sensitive personal, business, or authentication-adjacent content. Storing this data on disk without access controls, retention limits, or explicit user consent increases the risk of unintended disclosure to other local processes or users.
The script captures a screenshot and structured JSON analysis of the user's LinkedIn inbox and writes both to disk without any explicit consent prompt, minimization, or retention controls. Because inbox content can contain private messages, contact details, and business-sensitive information, storing these artifacts in a local output directory increases the risk of unauthorized disclosure from other processes, users, backups, or later agent use.
The script sends a LinkedIn message immediately after typing it by pressing Enter, with no preview, confirmation, or approval gate. In the context of an inbox automation skill that operates during off-hours and drafts responses automatically, this creates a real risk of unintended, malformed, or contextually wrong outbound messages being irreversibly sent to external parties.
The config fixes the locale-related setting to "America/Los_Angeles", which can impose a specific regional behavior without user opt-in. Under the policy, locale constraints should either be optional or clearly justified as region-specific.
No suspicious patterns detected.