Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- index.js:11
- Evidence
const BASE_URL = (process.env.SUPERAGNT_API_URL || 'https://api.superagnt.com') + '/v1/data/linkedin'
Security audit
Security checks for vulnerabilities and agentic risk
This plugin coherently exposes LinkedIn data lookup tools through Superagnt and does not show hidden, destructive, or unrelated behavior.
Install only if you intend to let agents query LinkedIn-related data through Superagnt. Treat the Superagnt API key as sensitive, review your organization’s privacy and LinkedIn data-use requirements, and be aware that tool inputs and requests are sent to the configured Superagnt API endpoint.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.env_credential_access
const BASE_URL = (process.env.SUPERAGNT_API_URL || 'https://api.superagnt.com') + '/v1/data/linkedin'