reddit-post-lead-scraper
Warn
Audited by Socket on Jul 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose matches Reddit lead scraping, but the skill’s footprint is widened by automatic transitive installation of BrowserAct and delegation of browsing to a third-party CLI that may access local browser session context. Official same-org install evidence lowers malware confidence, yet the auto-install/no-confirmation behavior and external runtime trust make this a medium-high security risk.
Confidence: 86%Severity: 69%
Audit Metadata