linkedin-company-posts-scraper

Warn

Audited by Socket on Jul 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s scraping purpose is plausible, but it relies on a third-party browser automation stack, expands scope beyond company posts into lead/contact enrichment, and instructs the agent to auto-install a separate skill/CLI without user confirmation. No direct credential theft or exfiltration endpoint is shown, so this is not confirmed malware, but the transitive install and autonomy patterns make it medium-high risk.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Jul 20, 2026, 04:30 AM
Package URL
pkg:socket/skills-sh/sam6dvpte34%2Flead-generation-skill%2Flinkedin-company-posts-scraper%2F@d44b32b3d53608909881caeb7476ec5753a1f73c80b16d53dea065db31242a0e
Security Audit — socket — linkedin-company-posts-scraper