career-ops
Audited by Socket on Aug 30, 2026
2 alerts found:
Anomalyx2No direct evidence of classic malware (data theft/backdoor/exfiltration/obfuscation) is present in the provided fragment. The primary concern is supply-chain execution risk inherent to this updater: it fetches and checks out remote Git content into local files and then runs `npm install`, which can execute lifecycle scripts from the updated dependency set. The safety gate helps prevent accidental modification of user-owned paths but is not a cryptographic integrity guarantee, and broad empty catch blocks reduce assurance about failure handling. Overall, treat this as a high-impact updater module and verify upstream trust/pinning and install script constraints before use.
SUSPICIOUS. The skill’s purpose is coherent with job-search automation, and the available install evidence is consistent with official Playwright usage rather than an unverified payload. The main risk is not malware but capability scope: it processes untrusted web content and can perform autonomous real-world actions like application assistance and portal scanning through subagents/browser automation.