Back to skill

Security audit

Linkedin API

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims, but it enables LinkedIn personal-data lookups and runs an unpinned third-party SDK without enough privacy or execution-safety guardrails.

Review this skill before installing. Use it only for authorized professional-data lookups, avoid contact-info or bulk enrichment unless you have a lawful purpose, keep returned personal data minimal, and run any generated uv scripts in a constrained environment with a pinned and reviewed linkdapi version plus only the required API key exposed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:17
Finding

Unpinned Third-Party Dependency Is Downloaded and Executed

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:157
Finding

Predictable Shared Temporary File Enables Symlink and Race Attacks

Content
View full analysis
/tmp/linkdapi_query.py << 'EOF' # /// script # dependencies = ["linkdapi"] # /// from linkdapi import LinkdAPI import os client = LinkdAPI(os.getenv("LINKDAPI_API_KEY")) profile = client.get_profile_overview("jeffweiner08") if profile.get('success'): data = profile['data'] print(f"Name: {data['fullname']}") print(f"Headline: {data.get('headline', 'N/A')}") print(f"Location: {data.get('location', 'N/A')}") print(f"Company: {data.get('company', 'N/A')}") else: print(f"Error: {profile.get('message')}") EOF uv run /tmp/linkdapi_query.py rm /tmp/linkdapi_query.py ``` ### Technical Analysis The example workflow uses the fixed path `/tmp/linkdapi_query.py` in a directory commonly shared by local users and processes. Shell redirection does not securely create the file and ordinarily follows symbolic links. The workflow also performs separate write, execution, and deletion operations without validating file ownership, type, or identity. A local attacker can pre-create the path as a symbolic link, potentially causing the shell to overwrite another file writable by the agent. Alternatively, an attacker able to modify the shared temporary directory can race the interval between script creation and `uv run`, replacing the intended script with attacker-controlled Python code. The final `rm` operation does not eliminate these risks because exploitation occurs during the preceding write or execution operation. It may also remove a path whose identity changed during the race. ### Attack Path **Symlink overwrite path:** 1. A local attacker predicts that the workflow will use `/tmp/linkdapi_query.py`. 2. The attacker creates that path as a symbolic link to a file writable by the agent. 3. The agent executes the documented `cat > /tmp/linkdapi_query ...[truncated 1255 chars]
Remediation
View remediation
"$tmp_script" << 'EOF' # Generated Python script EOF uv run "$tmp_script" ``` The execution environment should additionally restrict filesystem access, inherited environment variables, and network egress to the minimum required for the API request. ]]>
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 179)May include surrounding context.

EOF

uv run /tmp/linkdapi_query.py rm /tmp/linkdapi_query.py

text

## Getting an API Key

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented get_contact_info(username) capability directly enables retrieval of potentially sensitive personal data such as email addresses, phone numbers, and websites, yet the skill offers no warning, consent requirement, or use restriction. This materially increases the risk of doxxing, unauthorized enrichment, targeted phishing, or privacy-law violations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is designed to collect LinkedIn profile, company, job, and related people data, but it provides no privacy, consent, or data-handling guidance. In an agent context, this omission can normalize bulk collection or enrichment of third-party professional data without clear authorization boundaries, creating privacy and compliance risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly instructs the agent to write and execute a temporary Python script with uv run, which expands behavior from a narrow SDK usage guide into general code execution. Even though the examples are benign, this pattern allows user-controlled inputs and added dependencies to be embedded into executable scripts, increasing the risk of arbitrary code execution, supply-chain exposure, and unsafe script generation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.