Back to skill

Security audit

LinkedIn Automation by Zich (BradAI's OpenClaw)

Security checks for vulnerabilities and agentic risk

Overview

This LinkedIn skill is mostly a disclosed browser-workflow helper, but it can affect a real public account and its scheduled-post instructions are under-scoped and injection-prone.

Install only if you are comfortable letting an agent work in a logged-in LinkedIn browser session. Review every generated post, comment, like, analytics request, and scheduled job before execution, and avoid using externally supplied post content without sanitizing it first. Be especially cautious with scheduled posts because the artifact suggests a main-session cron event that can run later with less immediate user oversight.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
scripts/post.sh:30
Finding

Untrusted Post Content Is Embedded Directly into Agent Workflow Instructions

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
scripts/schedule.sh:27
Finding

Unsafe Post Content Interpolation into a Scheduled Main-Session System Event

Content
View full analysis
}, "payload": { "kind": "systemEvent", "text": "Post to LinkedIn now: $CONTENT" }, "sessionTarget": "main" } ``` ### Technical Analysis The script places attacker-influenced `$CONTENT` directly inside a quoted JSON string without JSON escaping. Quotes, backslashes, control characters, and newlines in the content can therefore make the displayed JSON invalid or alter its apparent structure. More importantly, the content is embedded into the `text` field of a future `systemEvent` targeting the `main` session: ```json "text": "Post to LinkedIn now: $CONTENT" ``` This converts untrusted post data into deferred agent instruction text. When the event executes, the main-session agent may interpret instruction-like content as trusted operational guidance rather than merely as text to publish. Scheduling the event also separates execution from the original review context, reducing the likelihood that a user will notice malicious or unintended instructions at execution time. The vulnerability does not establish system-level persistence by itself because the script only prints scheduling instructions and does not directly install a cron job. The confirmed issue is unsafe generation of a proposed scheduled event payload. ### Attack Path 1. An attacker controls or influences the content supplied to `scripts/schedule.sh`. 2. The content contains JSON-breaking characters, additional apparent field ...[truncated 1306 chars]
Remediation
View remediation
Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The description promises a broad LinkedIn automation capability covering content creation, posting, scheduling, engagement tracking, analytics, commenting, and audience growth. The actual code does not perform those actions. It simply echoes a text-based workflow for manually engaging with LinkedIn posts and provides sample comment templates and best practices. While commenting/engagement is thematically related to the declared purpose, the implementation is materially narrower and non-automated, making the description inaccurate for this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

There is a clear description-behavior mismatch. The declared purpose describes a broad LinkedIn automation suite with posting, scheduling, analytics, engagement, commenting, and growth capabilities. In contrast, the actual code is narrowly limited to formatting a scheduled-post template and showing the user how to create an OpenClaw cron job manually. It does not automate posting itself, does not access LinkedIn or a browser, and implements none of the analytics or engagement-related features named in the description. While scheduling is mentioned in both, the implementation is only an instructional helper, not the broader LinkedIn automation functionality claimed.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
97% confidence
Finding

The script emits browser-executable workflow instructions that interpolate untrusted user-controlled content directly into the output. In an agent setting, this creates a prompt/command injection surface: crafted post content can alter the downstream agent's behavior, especially because the skill is explicitly designed to drive a logged-in browser session on LinkedIn. The skill context makes this more dangerous because the instructions target a privileged authenticated session and could be repurposed to perform unintended actions or exfiltrate data via the browser tool.

Content

Scanner excerpt · scripts/post.sh (reported line 29)May include surrounding context.

sh
exit 1
fi

# Output instructions for the agent to execute via browser tool
cat << EOF
📝 LINKEDIN POST WORKFLOW
═══════════════════════════════════════

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description is broad enough that an agent may invoke it for many generic LinkedIn-related requests, increasing the chance of unintended activation in a logged-in browser context. Because the skill is designed to operate on a real user account, overbroad matching can cause unintended account actions or privacy-impacting automation on the user's behalf.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The top-level description lacks boundaries on when the skill should and should not activate, which is risky for an automation skill tied to an authenticated social-media session. In context, accidental activation could trigger browsing, posting, or engagement workflows against the user's LinkedIn account without sufficiently specific intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill describes automated posting and scheduling against a logged-in LinkedIn account without warning that it can create public content, affect reputation, or violate platform policies. In this context, browser-based account automation is especially sensitive because mistakes can publish content publicly, expose private business plans, or trigger account restrictions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Engagement automation is documented without clearly warning that likes and comments will be executed on the user's behalf, potentially creating public interactions they did not intend. In a logged-in social account context, this can damage professional reputation, leak preferences or affiliations, and create hard-to-reverse account activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This shell script includes a step to note who the user engaged with, which involves collecting or recording information about other individuals. There is no accompanying disclosure or caution about privacy considerations, data handling, or where that tracking should be stored.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.