he4rt-twitter-engagement-tracker

Warn

Audited by Socket on Jun 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the main extension design is broadly aligned with Twitter engagement tracking, but the skill’s footprint expands from local passive capture to autonomous third-party export of detailed interaction data. No strong malware or supply-chain indicators are present, yet the webhook/auto-push patterns and API-key handling make the skill medium-high risk.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 12, 2026, 07:45 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fmarketing-skills%2Fhe4rt-twitter-engagement-tracker%2F@ad18b62015cf42006dd1fd5a27827304bc6b0598bba46118b1012261ada4932a
Security Audit — socket — he4rt-twitter-engagement-tracker