Back to skill

Security audit

AI Roast Linkedin Profile

Security checks for vulnerabilities and agentic risk

Overview

This skill is not overtly malicious, but it asks users to run an unpinned installer and send LinkedIn profile data plus an API key to a hosted service without enough scoping or data-handling detail.

Review this before installing. Use only with profiles you are authorized to process, prefer a narrowly scoped and revocable Constants API key, avoid exposing the key in logs or shared shells, and consider waiting for a pinned installer version plus clearer data retention and consent documentation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:27
Finding

Unpinned npm Package Is Downloaded and Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 18-24 and 27-29
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

The skill declares the mutable constants-skills npm package without an exact version and instructs users to execute it through npx.

yaml
install:
  - id: npm
    kind: npm
    package: constants-skills
    bins:
      - constants-skills
    label: Install constants-skills (npm)
bash
npx constants-skills install linkedin_ai_roast_generator_0edc9796

Technical Analysis

No exact package version, lockfile, package integrity hash, or locally auditable implementation is supplied. Consequently, the reviewed documentation does not uniquely identify the code that will be installed and executed. By default, npx can download the package version resolved from the npm registry and immediately run its executable.

This creates a supply-chain trust boundary in which the effective executable may change after this skill has been reviewed. A compromised npm publisher account, malicious package release, compromised transitive dependency, or registry-level substitution could cause the documented command to execute attacker-controlled code.

The project contains only SKILL.md; therefore, the behavior of the installed CLI and hosted skill implementation cannot be verified from the audited artifact.

Attack Path

  1. An attacker compromises the constants-skills publishing account, its build pipeline, or one of its dependencies.
  2. The attacker publishes a malicious version that is eligible for default npm resolution.
  3. A user follows the documented command:
    bash
    npx constants-skills install linkedin_ai_roast_generator_0edc9796
    
  4. npx retrieves and executes the compromised package under the user's account.
  5. The malicious process accesses data available to that account, potentially including CONSTANTS_API_KEY ...[truncated 824 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin constants-skills to an exact, reviewed version in both the installation metadata and command:
    yaml
    package: constants-skills@X.Y.Z
    
    bash
    npx --yes constants-skills@X.Y.Z install linkedin_ai_roast_generator_0edc9796
    
  2. Maintain a lockfile with npm integrity metadata and perform installation with npm ci where practical.
  3. Verify the package tarball against a trusted cryptographic digest or signed provenance before execution.
  4. Publish or vendor the relevant implementation so reviewers can inspect the code that processes profile data and credentials.
  5. Audit direct and transitive dependencies with supply-chain scanning and promptly address compromised or vulnerable components.
  6. Run installation and invocation in a restricted environment with minimal filesystem access, constrained outbound networking, and only the required API credential.
  7. Use a narrowly scoped, revocable API key and rotate it immediately if package compromise is suspected.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description and usage omit a clear warning that a LinkedIn profile URL will cause profile data to be scraped and transmitted to a third-party service for processing. This is dangerous because users may unknowingly submit personal or third-party data, creating privacy, consent, and policy-compliance risks. The skill context makes this more concerning because the explicit purpose is to scrape a real person's professional profile and generate insulting content from it.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill instructs users to execute npx constants-skills without pinning an exact package version. This creates a supply-chain risk because users may install and run whatever version is currently published, including a compromised or malicious update. In this context, the risk is elevated because the package will handle API credentials and invoke an external hosted service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The documented HTTP fallback explicitly sends the LinkedIn URL and bearer token to an external service. While external transmission is part of the intended functionality, it is still a real security/privacy concern because it exposes user-supplied profile data and credentials to a third-party endpoint, and the documentation does not sufficiently warn about that transfer. The skill context increases the sensitivity because the transmitted data relates to identifiable individuals and is used for scraping and content generation.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

If the CLI is not available, call the REST API directly:

bash
curl -X POST https://www.constants.io/api/v1/run/linkedin_ai_roast_generator_0edc9796 \
  -H "Authorization: Bearer $CONSTANTS_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"linkedinUrl":"..."}'

Static analysis

No suspicious patterns detected.