T01 · Skill Instruction Hijacking
- Location
scripts/post.sh:30- Finding
Untrusted Post Content Is Embedded Directly into Agent Workflow Instructions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This LinkedIn skill is mostly a disclosed browser-workflow helper, but it can affect a real public account and its scheduled-post instructions are under-scoped and injection-prone.
Install only if you are comfortable letting an agent work in a logged-in LinkedIn browser session. Review every generated post, comment, like, analytics request, and scheduled job before execution, and avoid using externally supplied post content without sanitizing it first. Be especially cautious with scheduled posts because the artifact suggests a main-session cron event that can run later with less immediate user oversight.
scripts/post.sh:30Untrusted Post Content Is Embedded Directly into Agent Workflow Instructions
scripts/schedule.sh:27Unsafe Post Content Interpolation into a Scheduled Main-Session System Event
The description promises a broad LinkedIn automation capability covering content creation, posting, scheduling, engagement tracking, analytics, commenting, and audience growth. The actual code does not perform those actions. It simply echoes a text-based workflow for manually engaging with LinkedIn posts and provides sample comment templates and best practices. While commenting/engagement is thematically related to the declared purpose, the implementation is materially narrower and non-automated, making the description inaccurate for this code chunk.
There is a clear description-behavior mismatch. The declared purpose describes a broad LinkedIn automation suite with posting, scheduling, analytics, engagement, commenting, and growth capabilities. In contrast, the actual code is narrowly limited to formatting a scheduled-post template and showing the user how to create an OpenClaw cron job manually. It does not automate posting itself, does not access LinkedIn or a browser, and implements none of the analytics or engagement-related features named in the description. While scheduling is mentioned in both, the implementation is only an instructional helper, not the broader LinkedIn automation functionality claimed.
The script emits browser-executable workflow instructions that interpolate untrusted user-controlled content directly into the output. In an agent setting, this creates a prompt/command injection surface: crafted post content can alter the downstream agent's behavior, especially because the skill is explicitly designed to drive a logged-in browser session on LinkedIn. The skill context makes this more dangerous because the instructions target a privileged authenticated session and could be repurposed to perform unintended actions or exfiltrate data via the browser tool.
exit 1
fi
# Output instructions for the agent to execute via browser tool
cat << EOF
📝 LINKEDIN POST WORKFLOW
═══════════════════════════════════════
The skill description is broad enough that an agent may invoke it for many generic LinkedIn-related requests, increasing the chance of unintended activation in a logged-in browser context. Because the skill is designed to operate on a real user account, overbroad matching can cause unintended account actions or privacy-impacting automation on the user's behalf.
The top-level description lacks boundaries on when the skill should and should not activate, which is risky for an automation skill tied to an authenticated social-media session. In context, accidental activation could trigger browsing, posting, or engagement workflows against the user's LinkedIn account without sufficiently specific intent.
The skill describes automated posting and scheduling against a logged-in LinkedIn account without warning that it can create public content, affect reputation, or violate platform policies. In this context, browser-based account automation is especially sensitive because mistakes can publish content publicly, expose private business plans, or trigger account restrictions.
Engagement automation is documented without clearly warning that likes and comments will be executed on the user's behalf, potentially creating public interactions they did not intend. In a logged-in social account context, this can damage professional reputation, leak preferences or affiliations, and create hard-to-reverse account activity.
This shell script includes a step to note who the user engaged with, which involves collecting or recording information about other individuals. There is no accompanying disclosure or caution about privacy considerations, data handling, or where that tracking should be stored.
No suspicious patterns detected.