Back to skill

Security audit

Linkedin Reply Handler

Security checks for vulnerabilities and agentic risk

Overview

This skill drafts and posts LinkedIn replies with user approval, and its reaction behavior is disclosed rather than hidden.

Before installing, understand that approving a post action may publish both a LinkedIn reply and a reaction to the target comment. Only use it with LinkedIn/Publora/Apify credentials you intend to grant for this workflow, and review the approval card carefully before posting.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The documentation introduces a behavioral requirement unrelated to the skill’s stated purpose: 'Never skip the reaction' and defaulting to reacting on the specific comment being replied to. That creates scope expansion from drafting/posting a reply into performing an additional engagement action on LinkedIn, which can cause unintended user actions, consent violations, or manipulative automation if the implementation follows the docs literally.

Static analysis

No suspicious patterns detected.