linkedin-post-comments-scraper

Warn

Audited by Socket on Jul 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated prospecting purpose matches LinkedIn scraping, and BrowserAct appears to be an official dependency, but the skill is high-friction from a trust perspective because it auto-installs a separate skill/CLI without confirmation and delegates live browser behavior to that external runtime. Risk comes more from transitive installation and autonomous browser execution against third-party content than from confirmed malicious behavior.

Confidence: 86%Severity: 71%
Audit Metadata
Analyzed At
Jul 20, 2026, 04:25 AM
Package URL
pkg:socket/skills-sh/sam6dvpte34%2Flead-generation-skill%2Flinkedin-post-comments-scraper%2F@6bd0474354ed0eaebfe99fbf8bf977f2badc7e0d48f367fc21f5b95a00752c2c
Security Audit — socket — linkedin-post-comments-scraper