linkedin-executive-lead-search

Warn

Audited by Socket on Jul 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's lead-search purpose is plausible, but its footprint is enlarged by mandatory third-party BrowserAct dependencies, automatic transitive skill installation, and possible use of local browser cookies/session state. Data flow appears aligned to browsing LinkedIn rather than obvious credential theft, but the auto-install and delegated browser-control model make the trust boundary disproportionate for a simple lead-search helper.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Jul 20, 2026, 04:25 AM
Package URL
pkg:socket/skills-sh/sam6dvpte34%2Flead-generation-skill%2Flinkedin-executive-lead-search%2F@f2bddbed649a6c1b676e46d349d0ec2bf2d054f998cd68aaf9bb76296b4ea937
Security Audit — socket — linkedin-executive-lead-search