Back to skill

Security audit

Linkedin API

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward LinkdAPI helper for LinkedIn data lookups, with privacy and dependency-trust considerations but no hidden or malicious behavior in the artifact.

Install only if you trust LinkdAPI and the Python package it installs. Keep the API key in an environment variable, review generated scripts before running them in sensitive workspaces, and use contact-info endpoints only for legitimate, authorized purposes with minimal retention or sharing of returned personal data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly enables retrieval of LinkedIn profile, company, and especially contact information, but provides no privacy, consent, or acceptable-use guardrails. That omission can lead agents to collect or expose personal data without verifying authorization, increasing the risk of privacy violations, policy breaches, or misuse of sensitive professional contact data.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.