Back to skill

Security audit

Linkup

Security checks for vulnerabilities and agentic risk

Overview

This Linkup search guide is not malicious, but it needs review because it broadly encourages web and LinkedIn scraping and gives setup examples that expose an API key in URLs or shell commands.

Install only if you are comfortable routing web-search and fetch tasks through Linkup. Avoid using it for sensitive personal data collection unless you have a clear, lawful reason and explicit user direction. Prefer a secure secret store or protected MCP secret mechanism for the API key; if you paste a real key into a URL or shell command, rotate it if it may have entered history, logs, or shared config.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:252
Finding

API Key Exposed Through URL Query Parameters and Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 252–256
Vulnerability Type: API credential exposure through insecure configuration
Risk Level: Medium

Vulnerable Code

markdown
| **VS Code / Cursor** | Add to MCP config: `{"servers":{"linkup":{"url":"https://mcp.linkup.so/mcp?apiKey=YOUR_API_KEY","type":"http"}}}` |
| **Claude Code** | `claude mcp add --transport http linkup https://mcp.linkup.so/mcp?apiKey=YOUR_API_KEY` |
| **Claude Desktop** | Download [MCPB bundle](https://github.com/LinkupPlatform/linkup-mcp-server/releases/latest/download/linkup-mcp-server.mcpb), double-click to install |

Auth format (v2.x): `apiKey=YOUR_API_KEY` in args. Old v1.x `env` format no longer works.

Technical Analysis

The Skill directs users to replace YOUR_API_KEY with a real Linkup API key embedded in an HTTPS URL query parameter. The Claude Code setup command also places the resulting credential-bearing URL directly in command-line arguments.

Although HTTPS protects the URL while it is transmitted over the network, it does not prevent local or intermediary disclosure. A credential in this location may be retained in:

  • Shell command history.
  • Process command-line metadata visible to other local processes or users, depending on operating-system controls.
  • MCP client configuration files.
  • Diagnostic reports and application logs.
  • Proxy, monitoring, or URL-access logs.
  • Screenshots, copied commands, and support bundles.

Sending authentication data to Linkup is necessary for the declared search functionality, and the documented destination is the expected Linkup service rather than an unrelated exfiltration endpoint. However, placing the key in a URL and explicitly requiring it in command arguments exceeds secure minimum credential-handling practices.

Attack Path

  1. A user replaces YOUR_API_KEY with a valid Linkup API key.
  2. The user runs the documented Claude Code command or s ...[truncated 1055 chars]
Remediation
View remediation

Remediation Suggestions

  • Prefer an authorization header, protected environment variable, operating-system credential store, or MCP client's native secret-management facility instead of a URL query parameter.
  • Do not place credentials directly in command-line arguments, because arguments may be exposed through process inspection and shell history.
  • Store secrets separately from ordinary MCP configuration and restrict secret-file permissions to the owning user.
  • Ensure clients, proxies, and diagnostics redact the apiKey parameter from logs and error messages.
  • If Linkup currently mandates query-parameter authentication, construct the authenticated URL at runtime from protected secret storage rather than asking users to type or persist the completed URL.
  • Clearly warn users about shell-history and configuration-file exposure, and provide platform-specific secure setup examples.
  • Rotate any key that may already have appeared in command history, logs, screenshots, or shared configuration.
  • Apply account-side key scoping, usage limits, monitoring, and revocation controls to reduce the impact of credential compromise.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description says to use this skill whenever the agent has access to Linkup search or fetch tools and lists a very wide range of applicable tasks. That can cause over-activation on ordinary web tasks, unnecessarily routing many requests through an external search/scraping workflow and increasing the chance of unintended data disclosure or unnecessary external retrieval.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The invocation guidance instructs the agent to read this skill before making any Linkup search or fetch call, but it does not define boundaries for when such calls are appropriate. In practice, this can normalize external search/scraping as the default path, which expands data exposure and makes it easier for the agent to perform unnecessary retrieval on user content or third-party sites.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The LinkedIn extraction section explicitly instructs scraping profile details, posts, comments, and commenter data without any warning about privacy, platform terms, or sensitive-data handling. This is dangerous because it operationalizes collection of potentially personal information at scale and may lead agents to gather more data than is necessary for the user's task.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill tells the agent to extract post comments and return each commenter's LinkedIn profile URL, which directly facilitates collection and redistribution of personal identifiers beyond many likely user needs. In context, this is more dangerous because the skill is a general-purpose web retrieval guide, so the pattern can be reused broadly for profiling, deanonymization, or contact-list building rather than a narrowly scoped research task.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.