linkedin-activity-scraper

Warn

Audited by Socket on Jul 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core purpose is coherent with LinkedIn scraping, but the skill expands trust by automatically installing and invoking a separate browser-act Skill/CLI, with no per-action confirmation and potential use of sensitive browser session data. BrowserAct appears to be an official same-org dependency, so this is not confirmed malware, but the transitive installation and automation footprint make it medium-to-high risk.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Jul 20, 2026, 04:35 AM
Package URL
pkg:socket/skills-sh/sam6dvpte34%2Flead-generation-skill%2Flinkedin-activity-scraper%2F@b6f43142a66e68c7d5cfd37f58a468f9da46e0ec5402a4e4e7ca677a62c7026b
Security Audit — socket — linkedin-activity-scraper