Back to skill

Security audit

LinkedIn商业情报采集

Security checks for vulnerabilities and agentic risk

Overview

This LinkedIn API skill is mostly read-only, but it includes automatic fallback instructions to unrelated Douyin endpoints that could send authenticated requests outside the expected LinkedIn scope.

Review this skill before installing. It needs a MaxHub API key and sends your LinkedIn search/profile queries to www.aconfig.cn. The main concern is that its automatic error fallback table includes unrelated Douyin API paths, so use only if you are comfortable auditing or constraining requests to /api/v1/linkedin/ and prefer a pinned, trusted installer command.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:18
Finding

Unpinned npm CLI Execution Creates a Mutable Supply-Chain Boundary

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:298
Finding

Unrelated Douyin Fallback Instructions Expand the Skill Beyond Its Declared LinkedIn Scope

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (101)

Hidden Instructions

High
Category
Prompt Injection
Confidence
91% confidence
Finding

This duplicated finding points to the same hidden-instruction issue: security-relevant routing depends on content embedded in non-obvious locations. Such patterns make auditing harder and can be used to smuggle unauthorized behaviors into an otherwise benign-looking skill.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
| 禁止行为 | 正确做法 |
|----------|----------|
| ❌ 自行拼接路径(如 `/api/v1/douyin/search/xxx`) | ✅ 使用 Action Table 或 `<!-- Full path: -->` 中的路径 |
| ❌ 猜测参数名(如把 `aweme_id` 写成 `video_id`) | ✅ 使用 Action Table 或 reference 文件中的参数名 |
| ❌ 假设 v1/v2/v3 参数兼容 | ✅ 降级时重新读取对应版本的参数文档 |
| ❌ 调用 `fetch_hot_search_list` 或 `app/v3/fetch_video_comments` | ✅ 使用替代端点(见废弃标注) |

Hidden Instructions

High
Category
Prompt Injection
Confidence
91% confidence
Finding

This duplicated finding points to the same hidden-instruction issue: security-relevant routing depends on content embedded in non-obvious locations. Such patterns make auditing harder and can be used to smuggle unauthorized behaviors into an otherwise benign-looking skill.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
| 禁止行为 | 正确做法 |
|----------|----------|
| ❌ 自行拼接路径(如 `/api/v1/douyin/search/xxx`) | ✅ 使用 Action Table 或 `<!-- Full path: -->` 中的路径 |
| ❌ 猜测参数名(如把 `aweme_id` 写成 `video_id`) | ✅ 使用 Action Table 或 reference 文件中的参数名 |
| ❌ 假设 v1/v2/v3 参数兼容 | ✅ 降级时重新读取对应版本的参数文档 |
| ❌ 调用 `fetch_hot_search_list` 或 `app/v3/fetch_video_comments` | ✅ 使用替代端点(见废弃标注) |

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is presented as a LinkedIn-only assistant, but the operational rules explicitly reference Douyin-specific paths, parameters, and deprecated endpoints. This mismatch creates instruction confusion and could cause the agent to invoke unrelated APIs or process data from the wrong service, undermining trust boundaries and increasing the chance of unintended external requests.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The security declaration claims all endpoints are legitimate read-only LinkedIn-style APIs, but later sections describe Douyin fallback behavior and unrelated endpoint families. Contradictory assurances are a red flag because they can mask broader data access than advertised and may mislead operators into approving unsafe network behavior.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

md
| "analyze" / "分析一下" | Switch to analyze mode |
| "compare with X" / "和X对比" | Add X as second query |

## Output Guidelines

1. **Language consistency** — ALL output matches user's detected language.
2. **Markdown links** — All URLs in `[text](url)` format.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The error-handling and downgrade logic is targeted at Douyin APIs, not the LinkedIn APIs declared in the manifest. In practice, this can steer the agent toward unintended alternative endpoints after errors, causing cross-service requests, inaccurate results, or external data transmission outside the user's expectation.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-company.md (reported line 11)May include surrounding context.

md
`GET /api/v1/linkedin/web/get_company_affiliated_pages`

<!-- Full path: /api/v1/linkedin/web/get_company_affiliated_pages -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-company.md (reported line 36)May include surrounding context.

md
`GET /api/v1/linkedin/web/get_company_associated_member_insights`

<!-- Full path: /api/v1/linkedin/web/get_company_associated_member_insights -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-company.md (reported line 61)May include surrounding context.

md
`GET /api/v1/linkedin/web_v2/get_company_call_to_actions`

<!-- Full path: /api/v1/linkedin/web_v2/get_company_call_to_actions -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-company.md (reported line 91)May include surrounding context.

md
`GET /api/v1/linkedin/web_v2/get_company_competitors`

<!-- Full path: /api/v1/linkedin/web_v2/get_company_competitors -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-company.md (reported line 122)May include surrounding context.

md
`GET /api/v1/linkedin/web_v2/get_company_employee_count_ranges`

<!-- Full path: /api/v1/linkedin/web_v2/get_company_employee_count_ranges -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-company.md (reported line 153)May include surrounding context.

md
`GET /api/v1/linkedin/web_v2/get_company_employees`

<!-- Full path: /api/v1/linkedin/web_v2/get_company_employees -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-company.md (reported line 191)May include surrounding context.

md
`GET /api/v1/linkedin/web_v2/get_company_grouped_locations`

<!-- Full path: /api/v1/linkedin/web_v2/get_company_grouped_locations -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-company.md (reported line 222)May include surrounding context.

md
`GET /api/v1/linkedin/web/get_company_job_count`

<!-- Full path: /api/v1/linkedin/web/get_company_job_count -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-company.md (reported line 247)May include surrounding context.

md
`GET /api/v1/linkedin/web/get_company_job_count`

<!-- Full path: /api/v1/linkedin/web_v2/get_company_job_count -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-company.md (reported line 273)May include surrounding context.

md
`GET /api/v1/linkedin/web/get_company_jobs`

<!-- Full path: /api/v1/linkedin/web/get_company_jobs -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-company.md (reported line 318)May include surrounding context.

md
`GET /api/v1/linkedin/web/get_company_jobs`

<!-- Full path: /api/v1/linkedin/web_v2/get_company_jobs -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-company.md (reported line 355)May include surrounding context.

md
`GET /api/v1/linkedin/web/get_company_people`

<!-- Full path: /api/v1/linkedin/web/get_company_people -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-company.md (reported line 382)May include surrounding context.

md
`GET /api/v1/linkedin/web/get_company_posts`

<!-- Full path: /api/v1/linkedin/web/get_company_posts -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-company.md (reported line 413)May include surrounding context.

md
`GET /api/v1/linkedin/web/get_company_posts`

<!-- Full path: /api/v1/linkedin/web_v2/get_company_posts -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-company.md (reported line 446)May include surrounding context.

md
`GET /api/v1/linkedin/web/get_company_profile`

<!-- Full path: /api/v1/linkedin/web/get_company_profile -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-company.md (reported line 475)May include surrounding context.

md
`GET /api/v1/linkedin/web/get_company_profile`

<!-- Full path: /api/v1/linkedin/web_v2/get_company_profile -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-company.md (reported line 512)May include surrounding context.

md
`GET /api/v1/linkedin/web_v2/get_company_similar_companies`

<!-- Full path: /api/v1/linkedin/web_v2/get_company_similar_companies -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-company.md (reported line 539)May include surrounding context.

md
`GET /api/v1/linkedin/web_v2/get_company_stock_quote`

<!-- Full path: /api/v1/linkedin/web_v2/get_company_stock_quote -->

### Parameters

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/api-company.md (reported line 572)May include surrounding context.

md
`GET /api/v1/linkedin/web_v2/get_discovery_relevant_to_company`

<!-- Full path: /api/v1/linkedin/web_v2/get_discovery_relevant_to_company -->

### Parameters

Static analysis

No suspicious patterns detected.