reddit-comment-lead-scraper

Warn

Audited by Socket on Jul 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose matches Reddit lead scraping, but the skill is riskier than necessary because it auto-installs a separate skill/CLI and may operate with browser cookies and authenticated session context. BrowserAct looks like a legitimate same-org dependency rather than an obvious malicious payload, so this is not confirmed malware; the main concerns are transitive trust, autonomous installation, and broad browser-data access.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
Jul 20, 2026, 04:17 AM
Package URL
pkg:socket/skills-sh/sam6dvpte34%2Flead-generation-skill%2Freddit-comment-lead-scraper%2F@0366ecc466b39d02a2818843f6be93f1b21b7bd8d52c96435ddf88f952b1e64e
Security Audit — socket — reddit-comment-lead-scraper