Real Skill packageSource verifiedClawHub registry

Tinker LinkedIn

Your agent crawls LinkedIn through the browser session you already have — profiles, search, connections, inbox, feed. No official API, no app review. Your cookies never leave the browser: API calls are a fetch() run inside the linkedin.com tab you shared (people-search navigates that tab to a LinkedIn search page and reads the results), and 1.2.1 DELETED the cookie-extraction, session-store and external-replay code from the package rather than leaving it switched off — there is no longer anything to store or steal…

Identity and source

Publisher attributionOscar Serraregistry owner unverified by skillvetai
Functional categoryBrowser Automation & RPAautomatically inferred · 62% rule confidence
Package forminstruction with code4 recorded files
Canonical sourceClawHub registryclawhub:globalcaos:linkedin-hack
Open canonical source ↗

Platform declarations

These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.

OpenClawnative officialProvenance: registry distribution

Independent structural checks

These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.

Claude Codeissues found
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 9/17/2026.claude/skills/linkedin-hack
1 structural issue
  • error: description exceeds the 1,024-character Agent Skills limit. SKILL.md

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenAI Codexissues found
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 9/17/2026.agents/skills/linkedin-hack
1 structural issue
  • error: description exceeds the 1,024-character Agent Skills limit. SKILL.md

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenClawissues found
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 9/17/2026skills/linkedin-hack
1 structural issue
  • error: description exceeds the 1,024-character Agent Skills limit. SKILL.md

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

Installation and inspection

This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.

clawhub install @globalcaos/linkedin-hack
clawhub inspect @globalcaos/linkedin-hack --version 1.2.2

Security evidence

SkillVetAI static result: high signal

This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.

Status
completed
Coverage
full text content
Files
4 / 4 inspected as text
Checked
9/17/2026, 5:03:13 PM
Scanner
0.1.3
Policy
1.0.3
2 automated findings
highInstructions or code access sensitive credential locationsSKILL.md:128 · confidence 85%keychain entry exists — checking would mean read
highInstructions or code access sensitive credential locationsscripts/linkedin.mjs:836 · confidence 85%keychain_entry: 'not checked — looking it up would read
2 High/Critical review queue entries
STATIC_SENSITIVE_CREDENTIAL_ACCESSpending
STATIC_SENSITIVE_CREDENTIAL_ACCESSpending
Open human review queue →
6 inferred permission indicators
  • network access — automatically inferred
  • filesystem read — automatically inferred
  • filesystem write — automatically inferred
  • credential access — automatically inferred
  • browser control — automatically inferred
  • external write action — automatically inferred
13 dependency and API indicators
  • api: 127.0.0.1.nip.io
  • api: 127.evil.example
  • api: 93.184.216.34
  • api: api.linkedin.com
  • api: clawhub.ai
  • api: evil.example
  • api: github.com
  • api: linkedin.com
  • api: linkedin.com.attacker.test
  • api: linkedin.com.evil.example
  • api: www.linkedin.com
  • api: www.linkedin.com.evil.example
  • api: wwwxlinkedin.com
External clawhub result: clean

This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.

Evidence checked
9/17/2026, 12:20:17 PM
Release binding
Matches this record
  • vt: clean
  • skillspector: suspicious
  • llm: clean

Recorded files

The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.

Package content hashsha256:9be044c5d788d75abf18d72f21da9229148dbd5d96ddd691fdd19e30d6069c50
Show up to 4 recorded paths
  • scripts/linkedin.mjs
  • SKILL.md
  • tests/cli.test.mjs
  • tests/origin.test.mjs

Source changelog

Copied the published 1; Deleted keychainGet; Added a strict per-command --top range (out-of-range values are rejected); The relay must now be a literal loopback IP; TOKEN_FILE is no longer in OWNED_FILES; reserve() and bumpActivity() now run under an O_EXCL lock file (linkedin-activity; Those passages now say API calls are an in-tab fetch() and search people navigates the tab to a LinkedIn searc

Release security diff

highCompared fixed releases 1.2.1 and 1.2.2; 2 finding and 0 permission indicators were added.

Both fixed releases were scanned under the current scanner and policy, so finding, permission and dependency changes are available.

Change reasons and limitations
  • new high finding
  • finding surface changed
  • dependency surface changed
  • file surface changed
  • content hash changed

Observed release history

These older immutable releases were observed by prior successful syncs. They remain recorded when a newer release becomes current.

1.2.19/9/2026sha256:f80b9133860021657f8ff8fa7ff295bf1f3f29d6eefb35cb0672ce8654911998
1.2.09/8/2026sha256:7b7df10bd155276595fee594107c265e53b3bd353fc4be9e6b37a63b742f8725