social-sbti

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core workflow is coherent for a social-media personality-card skill, but trust is weakened by unseen Python dependencies and by forwarding X credentials/session data to an unofficial third-party client (Twikit). No direct malware or clear exfiltration endpoint is shown, yet the privacy-sensitive purpose and third-party credential handling make this a medium-to-high security risk skill.

Confidence: 82%Severity: 64%
Audit Metadata
Analyzed At
Apr 11, 2026, 11:35 AM
Package URL
pkg:socket/skills-sh/Backtthefuture%2Fhuangshu%2Fsocial-sbti%2F@f9254b3edb90ab1d15ac92c50b324beb5cecc238