T08 · Insecure Dependencies
- Location
SKILL.md:17- Finding
Unpinned Third-Party Dependency Is Downloaded and Executed
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill does what it claims, but it enables LinkedIn personal-data lookups and runs an unpinned third-party SDK without enough privacy or execution-safety guardrails.
Review this skill before installing. Use it only for authorized professional-data lookups, avoid contact-info or bulk enrichment unless you have a lawful purpose, keep returned personal data minimal, and run any generated uv scripts in a constrained environment with a pinned and reviewed linkdapi version plus only the required API key exposed.
SKILL.md:17Unpinned Third-Party Dependency Is Downloaded and Executed
SKILL.md:157Predictable Shared Temporary File Enables Symlink and Race Attacks
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
EOF
uv run /tmp/linkdapi_query.py rm /tmp/linkdapi_query.py
## Getting an API Key
The documented get_contact_info(username) capability directly enables retrieval of potentially sensitive personal data such as email addresses, phone numbers, and websites, yet the skill offers no warning, consent requirement, or use restriction. This materially increases the risk of doxxing, unauthorized enrichment, targeted phishing, or privacy-law violations.
The skill is designed to collect LinkedIn profile, company, job, and related people data, but it provides no privacy, consent, or data-handling guidance. In an agent context, this omission can normalize bulk collection or enrichment of third-party professional data without clear authorization boundaries, creating privacy and compliance risk.
The skill explicitly instructs the agent to write and execute a temporary Python script with uv run, which expands behavior from a narrow SDK usage guide into general code execution. Even though the examples are benign, this pattern allows user-controlled inputs and added dependencies to be embedded into executable scripts, increasing the risk of arbitrary code execution, supply-chain exposure, and unsafe script generation.
No suspicious patterns detected.