Back to skill

Security audit

SocQ LinkedIn Research

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed integration for using SocQ to research public LinkedIn data, with expected external API use and paid-credit considerations.

Install this only if you are comfortable sending LinkedIn research targets and related query inputs to SocQ, using a SocQ API key, and potentially spending SocQ credits. Prefer environment-based credentials, review credit limits, and avoid using sensitive or private data as search inputs unless your organization has approved SocQ for that use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The manifest explicitly routes LinkedIn research activity to a hosted third-party MCP endpoint, but it provides no user-facing disclosure that prompts, search terms, and possibly derived research targets will be transmitted off-platform. This creates a real privacy and data-governance risk because users or downstream agents may send sensitive investigative queries under the assumption the skill operates locally or within a trusted boundary.

External Transmission

Medium
Category
Data Exfiltration
Content
value: "socq"
      description: "Hosted SocQ LinkedIn data tools"
      transport: "streamable_http"
      url: "https://api.socq.ai/mcp?platforms=linkedin"
Confidence
88% confidence
Finding
https://api.socq.ai/

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.