Back to skill

Security audit

LinkedIn Inbox Manager

Security checks for vulnerabilities and agentic risk

Overview

This LinkedIn inbox skill is mostly purpose-aligned, but it can read private messages and send LinkedIn messages through a live browser session without strong built-in approval, recipient verification, or retention controls.

Review before installing. Use only with a dedicated browser profile or account, restrict the Discord channel, avoid retaining screenshots unless necessary, and do not rely on the included send script unless you add an explicit approval token, stable recipient verification, rate limiting, and fail-closed UI checks.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Unpinned Third-Party Dependency Receives Privileged System Access

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/scan_inbox.sh:7
Finding

Private LinkedIn Captures Are Written to Predictable Temporary Paths

Content
View full analysis
"$OUTPUT_DIR/inbox_$TIMESTAMP.json" 2>/dev/null || \ peekaboo image \ --app "Google Chrome" \ --path "$SCREENSHOT_PATH" ``` The conversation-opening script uses another predictable path: ```bash OUTPUT_PATH="/tmp/linkedin-conversation-$(date +%s).png" peekaboo see \ --app "Google Chrome" \ --annotate \ --path "$OUTPUT_PATH" ``` ### Technical Analysis The scripts save screenshots of LinkedIn inboxes and conversations, as well as UI-analysis JSON, beneath `/tmp` using timestamp-derived names. They do not establish a restrictive `umask`, atomically create a private directory, validate ownership, reject symbolic links, set explicit file permissions, or remove captures after use. Inbox screenshots and analysis output can contain names, message previews, private conversation text, professional relationships, and browser-interface metadata. Predictable timestamps make the paths easier for a local adversary to anticipate. On systems where the effective directory or files are writable or observable by another local principal, an attacker may monitor generated artifacts or prepare path objects before execution. Symbolic-link behavior ultimately depends on the invoked tool and operating-system protections, but the scripts do not independently enforce safe path ownership or file type. The optional user-controlled output directory in `scan_inbox.sh` can also cause sen ...[truncated 1334 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/send_message.sh:26
Finding

Message-Sending Script Does Not Enforce Approval or Verify the Selected Recipient

Content
View full analysis
/dev/null || true sleep 0.5 # Clear any existing text and type new message peekaboo type "$MESSAGE_TEXT" --app "Google Chrome" # Send with Enter echo "Sending..." peekaboo press return --app "Google Chrome" ``` The documented safety requirement states: ```markdown 1. **Never send without explicit approval** - Always wait for user confirmation 2. **Rate limit actions** - Max 20 LinkedIn actions per hour 3. **Respect quiet hours** - Don't scan outside configured activeHours 4. **Log everything** - Record all actions in daily memory file 5. **Preserve originals** - Never delete messages, only archive ``` ### Technical Analysis The message-sending script accepts a conversation name and message as command-line arguments and sends immediately. It does not verify that the content has received explicit user approval, even though the skill documentation identifies approval as mandatory. Recipient selection is also ambiguous. The script enters a display name, presses the down arrow, and selects the first search result without checking a stable LinkedIn profile identifier, profile URL, conversation identifier, or the visible identity of ...[truncated 2539 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents a LinkedIn inbox management assistant focused on scanning messages, drafting replies, approval workflows, and summaries. The supplied code does not implement those behaviors. Instead, it performs a narrow browser automation task: opening Chrome, navigating to a LinkedIn messaging URL for a specified person, and taking a screenshot. Screenshot capture of conversation content is a substantive capability not mentioned in the description, and the primary purpose is materially different from inbox management and response drafting.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a broader LinkedIn inbox management skill that scans messages, drafts replies, follows user style, and supports approval workflows and summaries. The supplied code only automates Chrome to open LinkedIn messaging and captures the inbox state as an image/JSON artifact. While this partially aligns with the 'scheduled scanning/monitoring' aspect, the primary implemented behavior is UI navigation and screenshot capture, and major declared capabilities like auto-drafting responses, approval flows, off-hours management, and summaries are absent. Additionally, the code uses undeclared browser automation and local file capture/storage of inbox contents, which are meaningful capabilities not reflected in the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The declared description emphasizes inbox management, scheduled monitoring, drafting replies, and approval-based workflows. The supplied code instead implements a narrow automation for directly sending a message to a named LinkedIn conversation through browser UI control. While LinkedIn messaging is related to the stated domain, the actual behavior omits the core declared features and includes immediate message sending without any visible approval step, which is materially different from the described approval-oriented drafting workflow.

Content

No source excerpt is available for this finding.

Context Leakage

High
Category
Data Exfiltration
Confidence
95% confidence
Finding

The screenshot operation captures the full LinkedIn conversation context from the live browser, which can expose message contents, participant identities, and other visible account data beyond the minimum needed for the task. In an inbox-management skill, this materially increases the chance of leaking sensitive communications or unrelated on-screen information through image files or downstream processing.

Content

Scanner excerpt · scripts/open_conversation.sh (reported line 28)May include surrounding context.

sh
peekaboo press return --app "Google Chrome"
sleep 3

# Capture the conversation
OUTPUT_PATH="/tmp/linkedin-conversation-$(date +%s).png"
peekaboo see \
    --app "Google Chrome" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill captures screenshots of LinkedIn inbox content and posts message previews and draft replies to an external notification channel, but the description does not clearly warn that private message contents and profile details may be collected, stored, and shared. This creates a meaningful privacy and data-handling risk, especially if the Discord channel is broader than intended or screenshots persist on disk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation phrase 'Start LinkedIn inbox monitoring' and similar natural-language triggers are broad enough that an agent could begin privacy-sensitive inbox scanning from an ambiguous or casually phrased request. Because this skill reads private messages and may draft or later send replies, unintended invocation could expose sensitive communications or trigger unwanted monitoring.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction to 'Log everything' in a daily memory file encourages retention of potentially sensitive LinkedIn message contents, sender identities, drafts, and user approval actions in natural-language memory. Such logs can become a secondary leakage source, be over-shared to other tools or agents, or persist longer than necessary without access controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script captures a screenshot of a LinkedIn conversation and writes it to /tmp, which may contain sensitive personal, business, or authentication-adjacent content. Storing this data on disk without access controls, retention limits, or explicit user consent increases the risk of unintended disclosure to other local processes or users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script captures a screenshot and structured JSON analysis of the user's LinkedIn inbox and writes both to disk without any explicit consent prompt, minimization, or retention controls. Because inbox content can contain private messages, contact details, and business-sensitive information, storing these artifacts in a local output directory increases the risk of unauthorized disclosure from other processes, users, backups, or later agent use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script sends a LinkedIn message immediately after typing it by pressing Enter, with no preview, confirmation, or approval gate. In the context of an inbox automation skill that operates during off-hours and drafts responses automatically, this creates a real risk of unintended, malformed, or contextually wrong outbound messages being irreversibly sent to external parties.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The config fixes the locale-related setting to "America/Los_Angeles", which can impose a specific regional behavior without user opt-in. Under the policy, locale constraints should either be optional or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.