domain-phone-enricher

Warn

Audited by Socket on Jul 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated contact-enrichment purpose is plausible, but the skill offloads work to an external browser automation ecosystem, instructs automatic dependency installation without separate approval, and may expose browser session context to third-party runtime components. Same-brand GitHub/PyPI evidence reduces the chance of outright malware, but the transitive-trust and browser-session risks are material.

Confidence: 82%Severity: 68%
Audit Metadata
Analyzed At
Jul 20, 2026, 04:19 AM
Package URL
pkg:socket/skills-sh/sam6dvpte34%2Flead-generation-skill%2Fdomain-phone-enricher%2F@157ecc65b04d2577eaac06ba04d575c24e3e7f6531c0f57227d939bda6748179
Security Audit — socket — domain-phone-enricher