github-project-contributor-finder-api-skill

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent and does not show classic malware or installer abuse, but it routes GitHub discovery through a third-party BrowserAct service and is explicitly aimed at collecting contributor contact/social data for recruiting and lead generation. Risk is moderate due to third-party credential forwarding and intermediary data collection, not confirmed malicious behavior.

Confidence: 83%Severity: 56%
Audit Metadata
Analyzed At
Apr 15, 2026, 06:06 AM
Package URL
pkg:socket/skills-sh/browser-act%2Fskills%2Fgithub-project-contributor-finder-api-skill%2F@67bbed37fda06c6f4c94b5b0567cb4c39629007d