T08 · Insecure Dependencies
- Location
README.md:18- Finding
Unpinned npm CLI Execution Creates a Mutable Supply-Chain Boundary
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This LinkedIn API skill is mostly read-only, but it includes automatic fallback instructions to unrelated Douyin endpoints that could send authenticated requests outside the expected LinkedIn scope.
Review this skill before installing. It needs a MaxHub API key and sends your LinkedIn search/profile queries to www.aconfig.cn. The main concern is that its automatic error fallback table includes unrelated Douyin API paths, so use only if you are comfortable auditing or constraining requests to /api/v1/linkedin/ and prefer a pinned, trusted installer command.
README.md:18Unpinned npm CLI Execution Creates a Mutable Supply-Chain Boundary
SKILL.md:298Unrelated Douyin Fallback Instructions Expand the Skill Beyond Its Declared LinkedIn Scope
This duplicated finding points to the same hidden-instruction issue: security-relevant routing depends on content embedded in non-obvious locations. Such patterns make auditing harder and can be used to smuggle unauthorized behaviors into an otherwise benign-looking skill.
| 禁止行为 | 正确做法 |
|----------|----------|
| ❌ 自行拼接路径(如 `/api/v1/douyin/search/xxx`) | ✅ 使用 Action Table 或 `<!-- Full path: -->` 中的路径 |
| ❌ 猜测参数名(如把 `aweme_id` 写成 `video_id`) | ✅ 使用 Action Table 或 reference 文件中的参数名 |
| ❌ 假设 v1/v2/v3 参数兼容 | ✅ 降级时重新读取对应版本的参数文档 |
| ❌ 调用 `fetch_hot_search_list` 或 `app/v3/fetch_video_comments` | ✅ 使用替代端点(见废弃标注) |
This duplicated finding points to the same hidden-instruction issue: security-relevant routing depends on content embedded in non-obvious locations. Such patterns make auditing harder and can be used to smuggle unauthorized behaviors into an otherwise benign-looking skill.
| 禁止行为 | 正确做法 |
|----------|----------|
| ❌ 自行拼接路径(如 `/api/v1/douyin/search/xxx`) | ✅ 使用 Action Table 或 `<!-- Full path: -->` 中的路径 |
| ❌ 猜测参数名(如把 `aweme_id` 写成 `video_id`) | ✅ 使用 Action Table 或 reference 文件中的参数名 |
| ❌ 假设 v1/v2/v3 参数兼容 | ✅ 降级时重新读取对应版本的参数文档 |
| ❌ 调用 `fetch_hot_search_list` 或 `app/v3/fetch_video_comments` | ✅ 使用替代端点(见废弃标注) |
The skill is presented as a LinkedIn-only assistant, but the operational rules explicitly reference Douyin-specific paths, parameters, and deprecated endpoints. This mismatch creates instruction confusion and could cause the agent to invoke unrelated APIs or process data from the wrong service, undermining trust boundaries and increasing the chance of unintended external requests.
The security declaration claims all endpoints are legitimate read-only LinkedIn-style APIs, but later sections describe Douyin fallback behavior and unrelated endpoint families. Contradictory assurances are a red flag because they can mask broader data access than advertised and may mislead operators into approving unsafe network behavior.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
| "analyze" / "分析一下" | Switch to analyze mode |
| "compare with X" / "和X对比" | Add X as second query |
## Output Guidelines
1. **Language consistency** — ALL output matches user's detected language.
2. **Markdown links** — All URLs in `[text](url)` format.
The error-handling and downgrade logic is targeted at Douyin APIs, not the LinkedIn APIs declared in the manifest. In practice, this can steer the agent toward unintended alternative endpoints after errors, causing cross-service requests, inaccurate results, or external data transmission outside the user's expectation.
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/linkedin/web/get_company_affiliated_pages`
<!-- Full path: /api/v1/linkedin/web/get_company_affiliated_pages -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/linkedin/web/get_company_associated_member_insights`
<!-- Full path: /api/v1/linkedin/web/get_company_associated_member_insights -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/linkedin/web_v2/get_company_call_to_actions`
<!-- Full path: /api/v1/linkedin/web_v2/get_company_call_to_actions -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/linkedin/web_v2/get_company_competitors`
<!-- Full path: /api/v1/linkedin/web_v2/get_company_competitors -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/linkedin/web_v2/get_company_employee_count_ranges`
<!-- Full path: /api/v1/linkedin/web_v2/get_company_employee_count_ranges -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/linkedin/web_v2/get_company_employees`
<!-- Full path: /api/v1/linkedin/web_v2/get_company_employees -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/linkedin/web_v2/get_company_grouped_locations`
<!-- Full path: /api/v1/linkedin/web_v2/get_company_grouped_locations -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/linkedin/web/get_company_job_count`
<!-- Full path: /api/v1/linkedin/web/get_company_job_count -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/linkedin/web/get_company_job_count`
<!-- Full path: /api/v1/linkedin/web_v2/get_company_job_count -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/linkedin/web/get_company_jobs`
<!-- Full path: /api/v1/linkedin/web/get_company_jobs -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/linkedin/web/get_company_jobs`
<!-- Full path: /api/v1/linkedin/web_v2/get_company_jobs -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/linkedin/web/get_company_people`
<!-- Full path: /api/v1/linkedin/web/get_company_people -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/linkedin/web/get_company_posts`
<!-- Full path: /api/v1/linkedin/web/get_company_posts -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/linkedin/web/get_company_posts`
<!-- Full path: /api/v1/linkedin/web_v2/get_company_posts -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/linkedin/web/get_company_profile`
<!-- Full path: /api/v1/linkedin/web/get_company_profile -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/linkedin/web/get_company_profile`
<!-- Full path: /api/v1/linkedin/web_v2/get_company_profile -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/linkedin/web_v2/get_company_similar_companies`
<!-- Full path: /api/v1/linkedin/web_v2/get_company_similar_companies -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/linkedin/web_v2/get_company_stock_quote`
<!-- Full path: /api/v1/linkedin/web_v2/get_company_stock_quote -->
### Parameters
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
`GET /api/v1/linkedin/web_v2/get_discovery_relevant_to_company`
<!-- Full path: /api/v1/linkedin/web_v2/get_discovery_relevant_to_company -->
### Parameters
No suspicious patterns detected.