email-address-extractor
Warn
Audited by Socket on Jul 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent, but it offloads its core behavior to an external BrowserAct skill/CLI and instructs automatic transitive installation without user confirmation. Same-org evidence makes this look more like elevated trust and prompt-injection/supply-chain risk than confirmed malware.
Confidence: 87%Severity: 64%
Audit Metadata