phone-number-extractor
Warn
Audited by Socket on Jul 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is plausible, but the skill is mostly a wrapper that delegates its core behavior to BrowserAct, instructs automatic installation without user confirmation, and introduces transitive trust plus live-web prompt-injection risk. The install sources look more consistent with the claimed publisher than a random third party, so this is not confirmed malware, but the skill’s operational footprint is broader and riskier than a simple phone-number extractor.
Confidence: 87%Severity: 72%
Audit Metadata