Skills linkedin-easy-apply
๐Ÿ“ฆ

linkedin-easy-apply

Content revision r1 High Risk โš™๏ธ External commands๐ŸŒ Network access๐Ÿ“ Filesystem access๐Ÿ”‘ Env variables

Automate LinkedIn Easy Apply Searches

Manual LinkedIn Easy Apply searches can be repetitive and inconsistent. This skill guides agents through a controlled Puppeteer workflow with filters, resume checks, and skip rules.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "linkedin-easy-apply" from https://skillstore.io/skills/ralyodio-linkedin-easy-apply.md and its manifest at https://skillstore.io/api/skills/ralyodio-linkedin-easy-apply/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "linkedin-easy-apply". Run a dry search for remote Codex and LLM engineer roles.

Expected outcome:

  • Scanned 40 Easy Apply roles matching the requested keywords.
  • Prepared 6 possible applications for review and submitted none because dry run was enabled.
  • Skipped 12 roles because the full description required hybrid work or unclear answers.

Using "linkedin-easy-apply". Apply to safe matches and stop before any compensation question.

Expected outcome:

  • Submitted 3 applications with verified resume facts.
  • Skipped 2 applications because compensation or custom essay fields were required.
  • Saved state so the next run can avoid duplicates.

Using "linkedin-easy-apply". Resume the daily run and summarize results.

Expected outcome:

The run skipped already-submitted roles, applied to safe matches, and reported each skipped role with a reason.

Security Audit

High Risk
v4 โ€ข 7/5/2026 Open versioned report

Most shell-backtick detections are false positives caused by Markdown fences and inline code. Confirmed risks include sandbox-disabled Chromium, persistent browser session storage, /tmp state logs, and automated personal data submission. No prompt injection or credential exfiltration instructions were found.

1
Files scanned
175
Lines analyzed
7
Review items
0
False positives ignored

Confirmed security concerns (3)

High
Environment file access
userDataDir: process.env.CHROME_PROFILE || `${process.env.HOME}/.cache/linkedin-chrome`,
The line configures a persistent Chrome user data directory that can hold authenticated LinkedIn session data. Reusing this profile is sensitive even without direct exfiltration.
High
UID/GID manipulation
args: ['--no-sandbox', '--disable-setuid-sandbox', '--disable-dev-shm-usage', '--start-maximized']
The Chromium launch arguments disable the browser sandbox and setuid sandbox. This weakens process isolation if LinkedIn or any loaded content is compromised.
Medium
Automated Personal Data Submission
The skill directs an agent to upload a resume and submit LinkedIn applications. This can expose personal data or submit unwanted applications if approval controls are weak.
The workflow explicitly searches LinkedIn Easy Apply, uploads a verified resume, and clicks submit when required fields are known. The context confirms automated third-party submission of personal job application data.
Capability review items (7)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Medium
Hidden file access
CHROME_PROFILE=$HOME/.cache/linkedin-chrome
The skill recommends a persistent hidden Chrome profile under the user home directory. That profile can retain LinkedIn session cookies and other browser state.
Medium
Hidden file access
userDataDir: process.env.CHROME_PROFILE || `${process.env.HOME}/.cache/linkedin-chrome`,
Puppeteer is configured to reuse a hidden browser profile path. Persistent profiles can expose authenticated session data if permissions or isolation are weak.
Medium
Temp directory access
STATE_DIR=/tmp/linkedin-easyapply-daily
The suggested state directory is under /tmp. Application state in a shared temporary path can be read or tampered with on multi-user systems.
Medium
Temp directory access
/tmp/linkedin-easyapply-daily/state.json
The state file path is under /tmp and can contain application status. Shared temporary storage creates privacy and integrity risk.
Medium
Temp directory access
/tmp/linkedin-easyapply-daily/results.jsonl
The results log path is under /tmp and can contain job URLs and submission outcomes. Shared temporary storage creates privacy and tampering risk.
Medium
Temp directory access
State: /tmp/linkedin-easyapply-daily/state.json
The reporting section exposes the state path under /tmp. That location is a weak default for user-specific application history.
Medium
Temp directory access
Log: /tmp/linkedin-easyapply-daily/results.jsonl
The reporting section exposes the log path under /tmp. Logs may include personal job search activity and should not use shared temporary storage.

Detected Patterns

UID/GID manipulation
Audited by: codex View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/ralyodio-linkedin-easy-apply/audits/4?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/ralyodio-linkedin-easy-apply/security.svg)](https://skillstore.io/skills/ralyodio-linkedin-easy-apply?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/ralyodio-linkedin-easy-apply?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/ralyodio-linkedin-easy-apply/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/ralyodio-linkedin-easy-apply.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

ralyodio. (2026). linkedin-easy-apply security audit report (audit version 4) [Author version unspecified]. Skillstore. https://skillstore.io/skills/ralyodio-linkedin-easy-apply/audits/4

BibTeX citation

@techreport{ralyodio-ralyodio-linkedin-easy-apply-2026, author = {ralyodio}, title = {linkedin-easy-apply security audit report (audit version 4)}, institution = {Skillstore}, year = {2026}, number = {4}, url = {https://skillstore.io/skills/ralyodio-linkedin-easy-apply/audits/4}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "linkedin-easy-apply security audit report (audit version 4)" version: "unspecified" type: report authors: - name: "ralyodio" date-released: "2026-07-05" url: "https://skillstore.io/skills/ralyodio-linkedin-easy-apply/audits/4" identifiers: - type: other value: "skillstore:ralyodio-linkedin-easy-apply:audit:4" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
68
Community
83
Spec Compliance

What You Can Build

Run a Focused Remote Job Search

Search Easy Apply roles with remote-only and keyword filters, then submit only safe matches.

Track Daily Application Progress

Reuse state files to avoid duplicate applications and report submitted or skipped roles.

Test Application Automation Rules

Validate resume-backed answer rules and skip behavior before enabling real submissions.

Try These Prompts

Set Up a Dry Run
Use the LinkedIn Easy Apply skill in dry-run mode. Configure my resume path, target keywords, location, and maximum scan count. Do not submit applications.
Search Remote AI Roles
Search LinkedIn Easy Apply for remote AI, LLM, and software engineer roles in the United States. Skip hybrid roles and any unclear required questions.
Review Before Submitting
Find matching Easy Apply roles and prepare each application with verified resume facts. Pause before final submission and show why each role is safe to submit.
Resume Daily Automation
Resume yesterday's LinkedIn Easy Apply run from the state file. Avoid duplicates, respect the apply limit, and report submitted, skipped, and already-submitted roles.

Best Practices

  • Start with dry-run mode and review every prepared application before enabling submission.
  • Use a dedicated browser profile and keep LinkedIn credentials out of scripts and logs.
  • Keep role keywords narrow and verify full job descriptions before applying.

Avoid

  • Do not reuse a primary personal browser profile for automation runs.
  • Do not fabricate applicant facts or infer approval from generic page text.
  • Do not submit applications when required fields are unclear or subjective.

Frequently Asked Questions

Does this skill store LinkedIn credentials?
No. It recommends manual login through a browser profile and warns against storing credentials in scripts or logs.
Can it submit applications automatically?
Yes, but only when the workflow finds no unknown required fields. Operator review is still the safer default.
Does it support remote-only searches?
Yes. It includes remote-only filtering and rechecks full job descriptions for hybrid or location constraints.
What happens with CAPTCHA or MFA?
The skill instructs the agent to stop for CAPTCHA, MFA, identity checks, and suspicious-login prompts.
Can it answer custom essay questions?
No. It skips custom essays, cover-letter prompts, compensation questions, and unclear required inputs unless approved.
Which tools can use this skill?
The report lists support for Claude, Codex, and Claude Code.

Developer Details

Author

ralyodio

License

MIT

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

62e2a730c5cd74eab4c7164309d810de660fcea3

Maintenance freshness

7/20/2026

Usage

3 downloads ยท 72 views

File structure

๐Ÿ“„ SKILL.md

More from ralyodio

View all
View all