last30
Warn
Audited by Socket on Aug 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill’s research behavior mostly matches its stated purpose and routes the X API key to the official xAI API, so this is not confirmed malware. The main concern is trust in local helper executables—especially ./secretcurl, which receives the credential before transmission—plus medium prompt-injection risk from processing untrusted external content while writing files and notifying. Overall classification: SUSPICIOUS due to credential forwarding through an unverifiable local binary, not due to the research workflow itself.
Confidence: 86%Severity: 82%
Audit Metadata