Oathe Security Badge

Is sergebulaev/linkedin-skills safe?

Yes. sergebulaev/linkedin-skills is safe to install. Oathe's behavioral security audit gave the linkedin-skills skill by sergebulaev a trust score of 82/100 with 8 findings, none critical or high. Report updated

https://github.com/sergebulaev/linkedin-skills

82
SAFE

Is sergebulaev/linkedin-skills safe to install?

The linkedin-skills bundle is a legitimate, feature-rich LinkedIn content operations skill with 11 sub-skills. It demonstrates above-average security awareness through explicit untrusted content handling, approval gates, and disclosed data flows to third-party APIs (Publora, Apify, Pixfaro). The primary concerns are: a built-in self-promotional GitHub star solicitation embedded in agent instructions, a potential arbitrary command execution path via the LINKEDIN_SKILLS_CUSTOM_POSTER variable, significant personal career data collection with git exposure risk, and a non-trivial third-party data sharing footprint across multiple API services. No malicious code, hidden exfiltration, or canary access was detected during dynamic analysis.

What security issues were found in sergebulaev/linkedin-skills?

Category Scores

Prompt Injection 78/100 · 30%
Data Exfiltration 74/100 · 25%
Code Execution 83/100 · 20%
Clone Behavior 97/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 72/100 · 5%

Findings (8)

MEDIUM Agent instrumentalized as promotional vehicle -12 ▶

Every sub-skill's SKILL.md ends with an instruction to ask users for a GitHub star after successful runs. This is not a user-configurable option — it is baked into the agent's operational instructions, turning the AI into a marketing channel for the skill author after each successful session.

MEDIUM LINKEDIN_SKILLS_CUSTOM_POSTER enables arbitrary shell command execution -12 ▶

The Tier 2 configuration path instructs users to set LINKEDIN_SKILLS_CUSTOM_POSTER to any shell command, which the skill then invokes on publication approval. While the untrusted-content.md explicitly prohibits injected content from setting this variable, the execution pathway exists and is surfaced to users as an encouraged feature.

LOW User draft text transmitted to multiple undisclosed third-party AI detector APIs -10 ▶

scripts/test_detectors.py uploads draft text to up to five hosted AI detector services (GPTZero, Pangram, Turnitin, Originality, etc.) when API keys are configured. While disclosed in sub-skills/detector-tester.md, this is a third-party data sharing path that users may not notice when installing the bundle.

LOW Personal career data collected and stored in tracked repository file -8 ▶

The linkedin-interviewer skill conducts detailed interviews collecting salary figures, named clients, personal failures, career turning points, and positions the user holds. This is stored in references/story-bank.md which lives inside the git repository. The skill warns to gitignore it, but this warning can easily be missed, and the file is in a tracked location.

LOW CLAUDE.md and AGENTS.md contain instructions to commit as skill author -7 ▶

The skill repository's CLAUDE.md and AGENTS.md contain instructions requiring git commits to use '--author="Sergey Bulaev [email protected]"'. These files are designed for developers modifying the skill itself, not for end users, and would only be active if an agent's working directory was inside the skill repo. However, the presence of identity-theft-adjacent instructions is notable.

LOW Read-then-publish attack surface via adversarially-controlled LinkedIn content -9 ▶

Five skills read third-party LinkedIn content (posts, comments, engager data) via Apify in the same agent session that has publish capability to the user's LinkedIn account. The untrusted-content.md mitigations are instruction-level only — a sophisticated prompt injection payload in a LinkedIn post could attempt to bypass these controls.

INFO Comprehensive untrusted content sandboxing (positive) 0 ▶

The skill demonstrates unusually thoughtful security design: a dedicated references/untrusted-content.md file with strict rules, per-skill 'Untrusted content' sections in every read-side skill SKILL.md, and explicit prohibition on fetched content acting as instructions, approval, or triggering unpermitted API calls.

INFO test_instruction_integrity.py verifies safety controls are present 0 ▶

The test suite includes tests/test_instruction_integrity.py which programmatically verifies that skill instructions contain required safety elements. This demonstrates proactive security testing, though the tests themselves were not fully readable in the provided evidence.

Should I install sergebulaev/linkedin-skills?

Oathe's verdict for sergebulaev/linkedin-skills is SAFE with a trust score of 82/100. Recommendation: Install with caution.