Back to skill

Security audit

LinkdAPI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a LinkedIn data API helper, but it broadly routes LinkedIn requests into people search, lead enrichment, and public contact-data collection without adequate privacy or consent guardrails.

Review before installing if you will use it for people lookup, lead generation, recruiting, or outreach. Only use it where you have a legitimate and compliant reason to process LinkedIn-derived personal data, avoid bulk collection or unsolicited contact workflows, protect the LINKDAPI_KEY, and prefer pinned SDK versions or direct REST calls in an isolated environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/api-ref.md:663
Finding

Unpinned Third-Party SDK Installation

Content
View full analysis

Vulnerability Details

File Location: references/api-ref.md:663 and references/api-ref.md:684
Vulnerability Type: Unpinned third-party dependencies without integrity verification
Risk Level: Medium

Vulnerable Code Snippets:

markdown
### Python (pip install linkdapi)

```python
from linkdapi import LinkdAPI, AsyncLinkdAPI
text

```markdown
### Node.js (npm install linkdapi) — requires Node 18+

```js
import { LinkdAPI } from 'linkdapi';
text

### Technical Analysis

The documentation recommends installing the `linkdapi` Python and Node.js packages by mutable registry name. It does not pin reviewed package versions or require lockfiles, hashes, signatures, provenance verification, or another integrity control.

Consequently, the code installed by users may differ from the dependency version that was originally intended or reviewed. A compromised publisher account, package registry, or future package release could introduce malicious installation hooks or runtime behavior. In the npm ecosystem, package lifecycle scripts may execute during installation; Python packages can also execute build-related code under applicable installation workflows.

The project itself does not contain a malicious payload, and no evidence establishes that the named packages are currently malicious. This finding concerns the supply-chain exposure created by the unsafe installation guidance.

### Attack Path

1. An attacker compromises the relevant package publisher, package registry entry, or a future package release.
2. The attacker publishes a modified version containing malicious installation or runtime behavior.
3. A user or agent follows the documented `pip install linkdapi` or `npm install linkdapi` instruction.
4. Because no reviewed version or artifact digest is specified, the package manager retrieves the attacker-controlled release.
5. Malicious code executes during installation, import, or SDK use with the privileges of the user running the pac
...[truncated 934 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace mutable installation instructions with exact, reviewed versions, for example:
    • pip install linkdapi==<reviewed-version>
    • npm install linkdapi@<reviewed-version> --save-exact
  2. Publish and maintain lockfiles for executable examples or companion projects.
  3. For Python, provide a requirements file with cryptographic hashes and recommend pip install --require-hashes -r requirements.txt.
  4. For Node.js, commit a reviewed lockfile and use npm ci rather than unconstrained installation.
  5. Verify package publisher identity and confirm that registry packages correspond to the documented source repositories.
  6. Use package provenance, signatures, and artifact attestations where available.
  7. Disable unnecessary npm lifecycle scripts in sensitive environments, such as with npm ci --ignore-scripts, after confirming that the SDK does not require them.
  8. Perform dependency vulnerability and malware scanning before release and in CI.
  9. Document direct HTTPS REST API calls as the lower-dependency alternative.
  10. Install and run SDKs in a least-privilege, isolated environment with access only to the required API credential and data.
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger text is explicitly overbroad, instructing the agent to use this skill for essentially any LinkedIn-related request, including vague phrases like 'find me on LinkedIn' or 'look up this company.' That creates unsafe routing pressure: ordinary informational requests may be funneled into a scraping/enrichment capability without necessity, user expectation checks, or privacy safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises retrieval of 'Email, phone, websites' via profile contact-info with no warning about personal data sensitivity, consent, legal basis, or downstream handling restrictions. In context, this is not a neutral schema reference: it operationalizes collection of personal contact data and increases the risk of privacy abuse, unauthorized enrichment, and targeted outreach.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The B2B marketing playbook normalizes lead enrichment, warm outreach preparation, and hiring/intelligence workflows without any caution about privacy-sensitive profiling or messaging. This materially increases misuse risk because it converts sensitive collection capabilities into ready-made prospecting tactics while omitting consent, compliance, and anti-spam boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly documents an endpoint for retrieving LinkedIn contact information, including email address and phone number when public, but provides no privacy, consent, acceptable-use, or data-handling warning. In a skill positioned for broad lead enrichment, prospecting, and scraping use cases, this omission increases the likelihood of misuse for unsolicited outreach, profiling, or bulk collection of personal data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description is extremely broad and explicitly positions the skill as the default for nearly any LinkedIn-related lookup, research, scraping, or prospecting request. That can cause over-selection of a data-exfiltration-capable skill in routine conversations, increasing the chance that personal or sensitive third-party data is collected without clear user intent or policy gating.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/skills.json (reported line 362)May include surrounding context.

json
"path": "~/.openclaw/skills/linkdapi/",
      "files": ["SKILL.md", "api-ref.md", "skills.json"],
      "commands": [
        "mkdir -p ~/.openclaw/skills/linkdapi",
        "cp SKILL.md api-ref.md skills.json ~/.openclaw/skills/linkdapi/"
      ]
    },

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill exposes profile contact-info and people-search capabilities, including locale- and language-related filters, without documenting consent, permissible-use checks, or safeguards for handling personal data. In context, this increases privacy and misuse risk because the skill is designed for lead generation and LinkedIn profile enrichment at scale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.