x-twitter-viral-radar

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/viral-timeline-template.py

No direct signs of stealth malware (no obfuscation, no in-module backdoor/persistence, no credential theft routines). However, this module has a high-impact security posture driven by supply-chain/control-plane risks: it executes an operator/config-controlled external helper (“webcmd”) via subprocess and forwards untrusted, operator-selected data to a configurable webhook over the network. If an attacker can influence VIRAL_RADAR_WEBCMD/--webcmd (or the PATH-resolved binary) they can gain arbitrary code execution; if they can influence webhook configuration they can cause exfiltration of tweet content/metadata. The snippet also appears corrupted in mark_delivered(), reducing confidence in exact SQLite behavior.

Confidence: 55%Severity: 75%
Audit Metadata
Analyzed At
Aug 1, 2026, 05:10 AM
Package URL
pkg:socket/skills-sh/agentrhq%2Fagent-automation-skills%2Fx-twitter-viral-radar%2F@1879e8a6d64412fb53320842b95495d4f1229a7614cf15786d789727a6f5be56
Security Audit — socket — x-twitter-viral-radar