Back to skill

Security audit

Linkedin Comment Drafter

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed LinkedIn comment drafter, but its public posting flow includes simulated-human timing and prospect-warmup guidance that should be reviewed before installation.

Install only if you want an agent to draft and, after explicit approval, post/react to LinkedIn comments through Publora or a manual route. Review the timing and sales-prospecting guidance against LinkedIn and Publora rules, and do not rely on it for automated engagement that simulates human behavior or scales outreach without careful user control.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The guidance to 'react before commenting' and pause 8-15 seconds so activity 'looks human' explicitly instructs behavior intended to mimic a real user and evade detection. In a comment-drafting skill, this expands functionality from content assistance into engagement automation tactics that may violate platform rules and expose users to account enforcement or deceptive-use risk.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The sales-oriented templates repurpose the skill for prospect warming and account-recognition building, which goes beyond user-requested comment drafting into covert outreach preparation. This can facilitate undisclosed lead-generation workflows and manipulative engagement on third-party posts, increasing misuse potential and policy/compliance risk.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description contains broad activation phrases like drafting or commenting on a LinkedIn post from a URL, which can overlap with common user requests and cause the agent to invoke this skill in situations where a narrower skill might be more appropriate. In this context, misrouting could lead to unintended social-media actions, including preparing or publishing comments against the user's actual intent if approval or context handling is weak elsewhere.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The 'When to use' section lists ambiguous trigger examples such as 'comment on this' and 'engage with this post' without strong exclusion boundaries, increasing the chance that an orchestrator will select this skill for loosely related requests. Because the skill can eventually call a publishing wrapper after approval, ambiguous routing raises the risk of drafting or scheduling public comments in the wrong workflow or on the wrong target.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The document encourages users to add reaction/comment timing and spacing specifically to make engagement appear human, but it provides no warning about platform-policy violations, deception concerns, or account suspension risk. That omission makes unsafe use more likely because users are nudged toward evasion-style behavior without informed consent about consequences.

Static analysis

No suspicious patterns detected.