lead-enrichment

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior fits lead enrichment, but the skill relies on an unspecified linkedin-scraper skill and a non-official LinkedIn scraping flow, creating medium supply-chain and data-flow uncertainty. No direct malware, credential theft, or explicit exfiltration is shown, but the transitive dependency and autonomous bulk record updates make the skill riskier than a normal documentation-only workflow.

Confidence: 79%Severity: 57%
Audit Metadata
Analyzed At
Mar 23, 2026, 11:18 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Flead-enrichment%2F@36b8a2b924a7e73f1da88b4332dbbd8ad077e88a