twitter-cli-skill

Warn

Audited by Socket on May 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s capabilities largely match its Twitter CLI purpose, and distribution via PyPI/GitHub is reasonably verifiable, but it is high-risk because it forwards browser cookies/raw session tokens to a third-party CLI, uses non-official auth methods with anti-detection features, and enables autonomous public posting and account actions. The main concern is disproportionate credential handling and action scope, not confirmed malware.

Confidence: 91%Severity: 81%
Audit Metadata
Analyzed At
May 18, 2026, 03:52 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fdevtools-skills%2Ftwitter-cli-skill%2F@74ff9e0830f3977fd5650d26a7fb8f68e52af0d7