github-project-contributor-finder-api-skill
Warn
Audited by Socket on Apr 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is internally coherent and does not show classic malware or installer abuse, but it routes GitHub discovery through a third-party BrowserAct service and is explicitly aimed at collecting contributor contact/social data for recruiting and lead generation. Risk is moderate due to third-party credential forwarding and intermediary data collection, not confirmed malicious behavior.
Confidence: 83%Severity: 56%
Audit Metadata