{"data":{"skill":{"slug":"ralyodio-linkedin-easy-apply","name":"linkedin-easy-apply","icon":"📦","repo":"https://github.com/ralyodio/agent-skills/tree/main/skills/linkedin-easy-apply-automation","status":"approved","author":"ralyodio","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"82676caa-3ee6-4407-9547-ec3da631a7fe","skill_id":"e6b9b745-11ec-4920-bc86-d52467a66a9f","version":2,"content_hash":"b668ef3c6a49acb7c82b6ebb28d8a103","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static code-execution and weak-crypto alerts are mostly false positives caused by Markdown backticks and keyword matching. The skill still has medium risk because it guides authenticated LinkedIn browser automation, persistent profile use, network access, and sandbox-disabled Chromium execution.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":72,"line_start":63}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":102,"line_start":99}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":52,"line_start":49},{"file":"SKILL.md","line_end":150,"line_start":148},{"file":"SKILL.md","line_end":165,"line_start":164}]},{"factor":"env_access","evidence":[{"file":"SKILL.md","line_end":69,"line_start":68}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Authenticated Browser Automation With Account Actions","locations":[{"file":"SKILL.md","line_end":45,"line_start":40},{"file":"SKILL.md","line_end":72,"line_start":63},{"file":"SKILL.md","line_end":132,"line_start":125}],"confidence":0.86,"description":"The skill directs an agent to use a logged-in LinkedIn browser session and submit applications. This is user-authorized automation, but it can act on an account and should require explicit operator control.","confidence_reasoning":"The instructions explicitly launch a browser profile and click through application submission steps. No evidence found of credential theft or unauthorized exfiltration."},{"title":"Persistent Browser Profile May Contain Session Data","locations":[{"file":"SKILL.md","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":69,"line_start":69}],"confidence":0.82,"description":"The skill recommends a persistent Chrome profile for manual LinkedIn login. That profile can contain cookies and session data, so storage permissions and cleanup matter.","confidence_reasoning":"The profile path is explicit and tied to authenticated browser use. The file does not instruct copying or transmitting the profile."},{"title":"Chromium Sandbox Disabled","locations":[{"file":"SKILL.md","line_end":71,"line_start":71}],"confidence":0.9,"description":"The Puppeteer launch arguments disable Chromium sandbox protections. This can increase impact if a browser exploit or malicious page is encountered.","confidence_reasoning":"The launch arguments directly include sandbox-disabling flags. This is a common container workaround, but it weakens browser isolation."}],"low_findings":[{"title":"Expected LinkedIn Network Access","locations":[{"file":"SKILL.md","line_end":102,"line_start":99}],"confidence":0.88,"description":"The hardcoded URL points to LinkedIn job application pages, which matches the stated purpose. No evidence found of third-party exfiltration endpoints.","confidence_reasoning":"The only observed hardcoded network destination is LinkedIn. This is expected for an Easy Apply automation skill."},{"title":"Temporary Logs May Contain Application History","locations":[{"file":"SKILL.md","line_end":150,"line_start":148},{"file":"SKILL.md","line_end":165,"line_start":164}],"confidence":0.78,"description":"The skill stores state and result logs under /tmp. These logs can expose job targets and application outcomes on shared systems.","confidence_reasoning":"The log and state paths are explicit. The exact logged fields are not implemented in this file, so the data exposure risk is limited."},{"title":"Static Analyzer Keyword Hits Are False Positives","locations":[{"file":"SKILL.md","line_end":59,"line_start":49},{"file":"SKILL.md","line_end":69,"line_start":68},{"file":"SKILL.md","line_end":172,"line_start":171}],"confidence":0.91,"description":"The Ruby backtick, weak-crypto, sensitive environment-file, and system-reconnaissance alerts come from Markdown formatting or ordinary text. No evidence found of those behaviors.","confidence_reasoning":"The referenced lines are Markdown examples, process environment configuration, or plain prose. They do not define Ruby execution, cryptography, .env access, or system reconnaissance."}],"dangerous_patterns":[{"title":"Sandbox-Disabled Browser Launch Pattern","locations":[{"file":"SKILL.md","line_end":72,"line_start":63}],"confidence":0.9,"description":"The Puppeteer configuration launches Chromium with sandbox protections disabled. This pattern should be avoided unless required by the runtime.","confidence_reasoning":"The sandbox flags are present in the documented launch arguments. The risk is contextual but technically clear."},{"title":"Persistent Authenticated Profile Pattern","locations":[{"file":"SKILL.md","line_end":42,"line_start":40},{"file":"SKILL.md","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":69,"line_start":69}],"confidence":0.84,"description":"The workflow relies on a reusable browser profile for manual login. This stores authenticated session material outside the skill file.","confidence_reasoning":"The safety rules and environment sample confirm persistent profile use. The skill also states it contains no credentials."},{"title":"Automated Submission Pattern","locations":[{"file":"SKILL.md","line_end":132,"line_start":125}],"confidence":0.87,"description":"The workflow allows clicking through review and final submission when required fields are known. This can create real-world account actions.","confidence_reasoning":"The multi-step loop explicitly includes final submission. It includes guardrails for unknown fields, reducing but not removing operational risk."}],"files_scanned":1,"total_lines":175,"audit_model":"codex","audited_at":"2026-06-30T10:56:13.766+00:00","created_at":"2026-06-30T11:57:09.496942+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":5,"needsReviewCount":0,"falsePositiveCount":1,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}