LinkedInSAFE
An MCP Server for Linkedin API
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MCP server for interacting with Linkedin Community Management API.
This MCP server:
- Can be hosted locally or remotely : uses HTTP+SSE transport defined in MCP
- Implements the Draft Third-Party Authorization Flow from MCP specs to delegate authorization to LinkedIn's OAuth authorization server
⚠️ Disclaimer: The Third-Party Authorization Flow proposal status is currently in draft. The only MCP client, to my knowledge, that currently implements this specification of the protocol is the MCP Inspector
Features
Tools
user-info- Get current logged in user infos (name, headline and profile picture)create-post- Create a new post on LinkedIn
Installation
Follow those instructions to run Linkedin MCP server on your host. You'll need to provide your own Linkedin client.
Requirements
- Node 22 (
lts/jod) - pnpm 10
- a Linkedin client with
Community Management APIproduct installed andhttp://localhost:3001/callbackadded to the authorized redirect URLs
Instructions
- Install dependencies:
pnpm install
- Create env file and populate with your Linkedin client credentials and a random string secret value for
JWT_SECRET:
cp .env.template .env && vi .env
- Run the server:
pnpm run dev
- Configure your favorite MCP client to use this new server:
{
"mcpServers": {
"linkedin": {
"url": "http://localhost:3001/sse"
}
}
}Debugging
Start the MCP Inspector to debug this server, which is available as a
c702e5934604OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add linkedin-mcp-server --env JWT_SECRET=${JWT_SECRET} --env LINKEDIN_CLIENT_SECRET=${LINKEDIN_CLIENT_SECRET} -- npx -y [email protected]{
"mcpServers": {
"linkedin-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"JWT_SECRET": "${JWT_SECRET}",
"LINKEDIN_CLIENT_SECRET": "${LINKEDIN_CLIENT_SECRET}"
}
}
}
}Exposed tools (2)
1 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
create-post | write | Create a new post on LinkedIn |
user-info | read | Get information about currently logged in LinkedIn user |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
.cursorignore
.env.template
axios, express, jsonwebtoken, linkedin-api-client, raw-body, vitest, zod, @types/express
Gates applied: no_behavioural_pass, no_license.
c702e5934604full audit observations/trust-audit/mcp-server/fredericbarthelet__linkedin-6.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | c702e5934604 | SAFE | B | 89 | first audit |
Questions
What is the LinkedIn MCP server?
An MCP Server for Linkedin API
What tools does LinkedIn expose?
2 in total: 1 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is LinkedIn safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does LinkedIn need?
It reads JWT_SECRET and LINKEDIN_CLIENT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does LinkedIn run?
It speaks sse, so it runs as a service you connect to over the network. It is published on npm as linkedin-mcp-server at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (c702e5934604), read on 2026-10-08. The repository is watched and re-audited when it changes.