Back to skill

Security audit

Linkedin Profile Audit

Security checks for vulnerabilities and agentic risk

Overview

The skill is transparent about editing LinkedIn, but it also keeps profile facts for later blog use and does not clearly require final approval before live profile changes.

Review this skill before installing. Use it only if you are comfortable letting an agent operate a logged-in LinkedIn browser session, and require a read-only extraction plus a visible diff before any save. Do not allow the memory log unless you explicitly want profile and employment facts retained for later writing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:126
Finding

Unnecessary Persistent Collection of LinkedIn Profile Facts

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 126
Vulnerability Type: other: Unnecessary Persistent Data Collection
Risk Level: Medium

Complete Code Snippet:

markdown
- Fact/data log in `memory/YYYY-MM-DD.md` for future blog post material

Technical Analysis

The skill directs the agent to persist a fact/data log in long-term memory after reviewing and correcting LinkedIn experience descriptions. This storage is not necessary to perform the profile audit or apply corrections. Its stated purpose—creating material for future blog posts—is separate from the user-requested profile-correction workflow.

The instruction does not require explicit user consent before storage, define which facts may be retained, exclude sensitive employment information, establish a retention period, or provide a deletion mechanism. Consequently, role clarifications, disputed claims, performance metrics, colleague relationships, and other employment details supplied during the audit could be retained beyond the original session.

This is not classified as T02 Agent Memory Poisoning because the instruction stores profile facts rather than attacker-controlled rules intended to alter future agent behavior. It is instead an unnecessary persistent-data-collection issue.

Attack Path

  1. The agent extracts experience descriptions from the user's authenticated LinkedIn profile.
  2. The agent asks the user for clarifications about metrics, deployments, responsibilities, commercial relationships, or contributions.
  3. The user supplies potentially sensitive employment facts to complete the audit.
  4. Following the output requirement, the agent writes those facts to memory/YYYY-MM-DD.md.
  5. The stored information remains available beyond the immediate audit and may later be retrieved or reused for blog content or other sessions without renewed contextual consent.

Impact Assessment

The issue does not grant opera ...[truncated 744 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the requirement to write profile facts to persistent agent memory because it is unrelated to the core audit and correction workflow.
  2. If retention is offered, make it a separate, explicit opt-in action rather than a default output.
  3. Display the exact proposed log contents and destination to the user before writing anything.
  4. Apply data minimization by excluding names, confidential metrics, disputed claims, partner details, and other information unnecessary for the user's approved purpose.
  5. Separate any user-approved notes from general long-term agent memory and restrict their use to the stated purpose.
  6. Define a retention period and provide a clear mechanism to inspect, edit, export, and delete stored records.
  7. Require renewed consent before reusing retained information for blog posts or any purpose outside the LinkedIn audit.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
- **Advisory ≠ Builder** — If you guided/directed others, say so. The people who coded it deserve credit, and peers will know the difference.
- **Design ≠ Deployment** — Never claim production metrics for work that didn't ship. Local PoCs are valuable — describe them honestly.
- **Tandem ≠ Led** — If someone else owned the non-technical or commercial side, reflect that explicitly.
- **AI-assisted is still yours** — Using Cursor, Claude, or Copilot to write code you directed and deployed doesn't diminish authorship. No caveat needed.
- **PoC/local ≠ Production** — "Built a working local proof-of-concept that validated the approach" is strong and honest. "Deployed to 100K users" when nothing went live is a liability.
- **Collaboration is a feature** — Saying "worked in tandem with the CEO" or "guided the Monash research team" signals leadership *and* honesty. Referees will confirm the accurate version.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill does state elsewhere that it will 'apply corrections live via Playwright,' but the output section does not present a clear, explicit warning immediately before or alongside the live-modification behavior. Because this skill edits a user's LinkedIn profile through an authenticated browser session, insufficient warning increases the risk of users triggering unintended permanent changes to public professional data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.