reddit-post-lead-scraper

Warn

Audited by Socket on Jul 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose matches Reddit lead scraping, but the skill’s footprint is widened by automatic transitive installation of BrowserAct and delegation of browsing to a third-party CLI that may access local browser session context. Official same-org install evidence lowers malware confidence, yet the auto-install/no-confirmation behavior and external runtime trust make this a medium-high security risk.

Confidence: 86%Severity: 69%
Audit Metadata
Analyzed At
Jul 20, 2026, 04:26 AM
Package URL
pkg:socket/skills-sh/sam6dvpte34%2Flead-generation-skill%2Freddit-post-lead-scraper%2F@73a6e0048d19089d1e5e29c8d99a20dcc240789ef8dc9532caf247c60f044095
Security Audit — socket — reddit-post-lead-scraper