Back to skill

Security audit

B2B Lead Generation Scraper

Security checks across malware telemetry and agentic risk

Overview

The skill appears related to LinkedIn automation, but it asks users to store a live LinkedIn login cookie without enough safety disclosure.

Review this carefully before installing. Only use a dedicated or low-risk LinkedIn account, treat LI_SESSION/li_at like a password, avoid logging or sharing it, rotate/revoke the session after use, and consider whether an official API or OAuth-based workflow is available instead.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill instructs users to extract and store a live LinkedIn session cookie (`li_at`) in a secrets manager, but provides no warning that this token grants account access and may expose the user's LinkedIn account if mishandled. In this context, the credential is especially sensitive because it is reused to automate scraping against a third-party service, increasing the risk of account takeover, unauthorized use, privacy violations, and account suspension if the secret is leaked or abused.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.