twitter-agent
Warn
Audited by Socket on Apr 25, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s capabilities broadly match its stated purpose, and its X API data flow is mostly coherent and direct. However, it grants an AI agent autonomous public-posting ability and forwards live X credentials into third-party npm code via execute_cli, creating meaningful trust and account-abuse risk even without clear evidence of credential theft or hidden exfiltration.
Confidence: 87%Severity: 69%
Audit Metadata