linkedin-company-posts-scraper
Warn
Audited by Socket on Jul 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s scraping purpose is plausible, but it relies on a third-party browser automation stack, expands scope beyond company posts into lead/contact enrichment, and instructs the agent to auto-install a separate skill/CLI without user confirmation. No direct credential theft or exfiltration endpoint is shown, so this is not confirmed malware, but the transitive install and autonomy patterns make it medium-high risk.
Confidence: 84%Severity: 68%
Audit Metadata