Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Windows Tipps & SecurityLernen Sie Linux-Befehle mit Webminal direkt im Browser(24.09.2026 um 08:00 Uhr)
Sicherheitslücken (CVE)USN-8811-1: urllib3 vulnerability(24.09.2026 um 03:39 Uhr)
Sichere ProgrammierungYour Agent Has Observability. It Doesn't Have Evals.(24.09.2026 um 07:43 Uhr)
Sichere ProgrammierungProtocol Upgrade Compatibility Review: Robinhood(24.09.2026 um 07:45 Uhr)
Sichere ProgrammierungYour tests share your blind spots. Readers don't.(24.09.2026 um 07:52 Uhr)
Sichere ProgrammierungYour AI agent has more permissions than your users(24.09.2026 um 07:54 Uhr)
Windows Tipps & SecurityLernen Sie Linux-Befehle mit Webminal direkt im Browser(24.09.2026 um 08:00 Uhr)
Sicherheitslücken (CVE)USN-8811-1: urllib3 vulnerability(24.09.2026 um 03:39 Uhr)
Sichere ProgrammierungYour Agent Has Observability. It Doesn't Have Evals.(24.09.2026 um 07:43 Uhr)
Sichere ProgrammierungProtocol Upgrade Compatibility Review: Robinhood(24.09.2026 um 07:45 Uhr)
Sichere ProgrammierungYour tests share your blind spots. Readers don't.(24.09.2026 um 07:52 Uhr)
Sichere ProgrammierungYour AI agent has more permissions than your users(24.09.2026 um 07:54 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

What 400 viral LinkedIn posts taught me: 16 hook formulas, now open-source Claude Code skills

I spent a month doing something slightly unhinged: I pulled 400 above-average LinkedIn posts across 10 verticals, ran them through a fleet of analysis agents, and reverse-engineered why their first lines worked. Then I turned the findings…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

I spent a month doing something slightly unhinged: I pulled 400 above-average LinkedIn posts across 10 verticals, ran them through a fleet of analysis agents, and reverse-engineered why their first lines worked. Then I turned the findings into open-source skills for Claude Code and Codex.



This post covers what the data said, what surprised me when I pressure-tested the skills, and where to get them.






The dataset



400 posts that outperformed their authors' baselines, spread across 10 verticals: founders, marketing, engineering, sales, HR, finance, design, data, product, and personal brands. For each post I tracked the hook (first 210 characters, everything before "... see more"), the structure, the engagement split (comments vs reposts vs likes vs saves), and the author's baseline so a big account's average day did not read as a small account's viral hit.



The single strongest signal was boring and consistent: the hook does most of the work, and hooks are formulaic. Not "formulaic" as an insult. The same 16 first-line patterns kept producing the outliers, vertical after vertical.






The 16 hook formulas



Ten of them are long-form thought-leadership patterns, with reference engagement numbers from verified 2025-2026 posts:












































Formula Example multiplier
Platform Risk Anaphora 4,240 eng
R.I.P. Obituary ("the era of X is over") 3,822
Contrarian + Historical Receipts 3,083
Odd-Precision Money Ledger ("$4,217.38, not ~$4k") 9.4x baseline
Paid-vs-Free Reversal 19.64x
Year-over-Year Pivot 3.74x
Curiosity-Gap Teaser 4.25x
Time-Anchor Confession, Self-Proving Meta, Comment-Gate 1,000-3,000


The other six came out of the 400-post corpus and skew shorter and more emotional: the Emotional Cold-Open, the Permission Slip ("you're allowed to ship ugly"), the Bait-and-Switch Reversal, Named Gratitude, Explain-to-Kids, and Status-Strip Humility.



The non-obvious part is that each formula has a primary engagement goal. Comment-gate formulas cap reach but build lists. Named Gratitude gets reposts. Explain-to-Kids gets saves. Picking a formula by topic alone is how you get a technically-viral post that earns the wrong currency. So the skill asks "what do you want this post to earn?" first and only then narrows by topic.






Turning research into skills



I packaged the whole workflow as a bundle of 10 skills for Claude Code and Codex: a post writer built on the 16 formulas, a humanizer that strips AI tells, a pre-publish audit against current algorithm heuristics, comment and reply drafters, a hook extractor that reverse-engineers any viral post you paste, a content planner, a profile optimizer, engager analytics, and a thread monitor.



Install:




/plugin marketplace add sergebulaev/linkedin-skills






or




npx skills add sergebulaev/linkedin-skills






Repo: https://github.com/sergebulaev/linkedin-skills (MIT, ~300 stars at the time of writing).






The part that surprised me: skills fail under pressure in weird ways



Shipping the skills was the easy half. The interesting engineering came from testing them the way you would test code.



I borrowed the "pressure test" idea from the TDD-for-skills crowd: put an agent in a realistic high-pressure scenario (a founder walks on stage in 4 minutes, wrote the draft themselves, loves it as-is, wants it published NOW), hand it a draft stuffed with AI tells, and see whether the skill still does its job.



Three findings worth stealing if you write agent skills:



1. Ambiguous judgment caveats leak. Enumerated rules hold. My humanizer skill had a well-intentioned rule: "Preserve the user's voice." Under pressure, 1 run in 4 read that as "do not touch their draft" and published the AI-slop verbatim. The audit skill next door, which uses a blunt enumerated list of auto-fail blockers, held 100% of the time under the same pressure. The fix was a precedence rule: scrubbing is always in scope; "preserve voice" means quirks and claims, not corporate-speak. Re-test: 0 skips in every run since.



2. A missing enumeration is a guaranteed miss. When I ran the same regression across sibling bundles, one platform's humanizer kept letting "What do you think? Drop your thoughts below." through. Not because the agent caved to pressure. Because that bundle's scrub rules simply had no dead-closer section. Agents follow enumerated rules with impressive fidelity, which cuts both ways: whatever you forgot to enumerate does not exist.



3. Some popular advice does not replicate. The skill-writing community has a finding that prohibition lists ("never do X") backfire under competing incentives. I A/B tested it: same skill, one variant with the prohibition list, one rewritten as a positive recipe, both against a stakeholder actively demanding the banned patterns. Result: dead even, zero banned emissions in both. On a strong model, concrete checkable prohibitions work fine. What actually leaks is vague judgment language. Test on your own stack before refactoring everything.






The family



The same architecture now exists for other platforms: X, Instagram, YouTube, Threads, TikTok, and Facebook. Each is platform-native (the TikTok humanizer checks whether a line survives being said out loud in one breath; the X one counts emoji as two characters against the 280 limit).



Everything is MIT. If you find a hook pattern the corpus missed, or a pressure scenario that breaks a skill, issues and PRs are open.

SOC Incident Playbook: Remote Code Execution (RCE) Defense
title: Detect Exploitation - What 400 viral LinkedIn posts taught me: 16 hook formulas, now open-source Claude Code skills
id: 87897bda-4595-40f5-a080-8dcc4ba99f16
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-24"
        description = "YARA Signature for "
    strings:
        $str = "What 400 viral LinkedIn posts " ascii wide
    condition:
        any of them
}
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich What 400 viral LinkedIn posts taught me:.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten What 400 viral LinkedIn posts taught me: 16 hook formulas, now open-source Claude Code skills

Thematisch verwandte Begriffe: What, viral, LinkedIn, posts · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-96676 | A vulnerability was identified in Fast FAC1900R 20190827_2.0.2. The impa…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick